CVE-2015-7197: Mozilla Firefox

Medium severity, CVSS 5.0. EPSS: 2.5% chance of exploitation in the next 30 days.

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly control the ability of a web worker to create a WebSocket object, which allows remote attackers to bypass intended mixed-content restrictions via crafted JavaScript code.

Affected products

  • Mozilla Firefox: up to and including 41.0.2; version 38.0 only; version 38.0.1 only; version 38.0.5 only; version 38.1.0 only; version 38.1.1 only; …

Published 2015-11-05. Last modified 2026-06-17.