CVE-2015-7207
Summary
| CVE | CVE-2015-7207 |
|---|---|
| State | PUBLISHED |
| Assigner | mozilla |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-12-16 11:59:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 22 Update: firefox-43.0-1.fc22 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [security-announce] openSUSE-SU-2016:0894-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Mozilla Firefox Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| openSUSE-SU-2015:2353-1: moderate: Security update for MozillaFirefox | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| openSUSE-SU-2016:0308-1: moderate: Security update for Seamonkey | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [SECURITY] Fedora 23 Update: firefox-43.0-1.fc23 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [security-announce] openSUSE-SU-2016:0876-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| openSUSE-SU-2016:0307-1: moderate: Security update for seamonkey | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| 1185256 - (CVE-2015-7207) performance.getEntries() shows x-domain URLs after a redirect when loading from cache | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Same-origin policy violation using performance.getEntries and history navigation — Mozilla | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| USN-2833-1: Firefox vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Cached redirects + History traversal reveal cross-origin URLs · Issue #29 · w3c/resource-timing · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Vendor Advisory |
| Mozilla Products: Multiple vulnerabilities (GLSA 201512-10) — Gentoo Security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Obtain Potentially Sensitive Information, Bypass Same-Origin Policy, and Cause Denial of Service Conditions - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.