CVE-2015-7204: Fedoraproject Fedora
Medium severity, CVSS 6.8. EPSS: 3.5% chance of exploitation in the next 30 days.
Mozilla Firefox before 43.0 does not properly store the properties of unboxed objects, which allows remote attackers to execute arbitrary code via crafted JavaScript variable assignments.
Affected products
- Fedoraproject Fedora: version 22 only; version 23 only
- Mozilla Firefox: up to and including 42.0; version 41.0 only; version 41.0.1 only; version 41.0.2 only
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.1 only; version 13.2 only
Published 2015-12-16. Last modified 2026-06-17.