CVE-2015-7188: Mozilla Firefox

High severity, CVSS 7.5. EPSS: 3.1% chance of exploitation in the next 30 days.

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to bypass the Same Origin Policy for an IP address origin, and conduct cross-site scripting (XSS) attacks, by appending whitespace characters to an IP address string.

Affected products

  • Mozilla Firefox: up to and including 41.0.2; version 38.0 only; version 38.0.1 only; version 38.0.5 only; version 38.1.0 only; version 38.1.1 only; …

Published 2015-11-05. Last modified 2026-06-17.