CVE-2015-4520: Mozilla Firefox

Medium severity, CVSS 6.4. EPSS: 3.1% chance of exploitation in the next 30 days.

Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to bypass CORS preflight protection mechanisms by leveraging (1) duplicate cache-key generation or (2) retrieval of a value from an incorrect HTTP Access-Control-* response header.

Affected products

  • Mozilla Firefox: version 38.0 only; version 38.0.1 only; version 38.0.5 only; version 38.1.0 only; version 38.1.1 only; version 38.2.0 only; …

Published 2015-09-24. Last modified 2026-06-17.