{"api_version":"1","generated_at":"2026-07-23T06:10:15+00:00","cve":"CVE-2015-4518","urls":{"html":"https://cve.report/CVE-2015-4518","api":"https://cve.report/api/cve/CVE-2015-4518.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-4518","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-4518"},"summary":{"title":"CVE-2015-4518","description":"The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors involving SVG animations and the about:reader URL.","state":"PUBLISHED","assigner":"mozilla","published_at":"2015-11-05 05:59:04","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.html","name":"http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] openSUSE-SU-2015:1942-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1034069","name":"http://www.securitytracker.com/id/1034069","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Obtain Potentially Sensitive Information, Bypass Security Restrictions, and Conduct Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1182778","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1182778","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"1182778 - (CVE-2015-4518) Passive script execution on about:reader via SVG animations (affects: Firefox, NoScript, CSP; impact: spoofing, phishing)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-2785-1","name":"http://www.ubuntu.com/usn/USN-2785-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-2785-1: Firefox vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2015/mfsa2015-118.html","name":"http://www.mozilla.org/security/announce/2015/mfsa2015-118.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"CSP bypass due to permissive Reader mode whitelist — Mozilla","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1136692","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1136692","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"1136692 - Reader Mode does not completely disable all active content (XSS)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201512-10","name":"https://security.gentoo.org/glsa/201512-10","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mozilla Products: Multiple vulnerabilities  (GLSA 201512-10) — Gentoo Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html","name":"http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Solaris Bulletin - April 2016","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-4518","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-4518","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"4518","vulnerable":"1","versionEndIncluding":"41.0.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T06:18:11.691Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1034069","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1034069"},{"name":"GLSA-201512-10","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201512-10"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/2015/mfsa2015-118.html"},{"name":"USN-2785-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2785-1"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1136692"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html"},{"name":"openSUSE-SU-2015:1942","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1182778"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-11-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors involving SVG animations and the about:reader URL."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-05T22:57:01.000Z","orgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","shortName":"mozilla"},"references":[{"name":"1034069","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1034069"},{"name":"GLSA-201512-10","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201512-10"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/2015/mfsa2015-118.html"},{"name":"USN-2785-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2785-1"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1136692"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html"},{"name":"openSUSE-SU-2015:1942","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1182778"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@mozilla.org","ID":"CVE-2015-4518","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors involving SVG animations and the about:reader URL."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1034069","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1034069"},{"name":"GLSA-201512-10","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201512-10"},{"name":"http://www.mozilla.org/security/announce/2015/mfsa2015-118.html","refsource":"CONFIRM","url":"http://www.mozilla.org/security/announce/2015/mfsa2015-118.html"},{"name":"USN-2785-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2785-1"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1136692","refsource":"CONFIRM","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1136692"},{"name":"http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html"},{"name":"openSUSE-SU-2015:1942","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.html"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1182778","refsource":"CONFIRM","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1182778"}]}}}},"cveMetadata":{"assignerOrgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","assignerShortName":"mozilla","cveId":"CVE-2015-4518","datePublished":"2015-11-05T02:00:00.000Z","dateReserved":"2015-06-10T00:00:00.000Z","dateUpdated":"2024-08-06T06:18:11.691Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-11-05 05:59:04","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionEndIncluding":"41.0.2","matchCriteriaId":"A741F21D-4095-47E0-AAB4-DDBDAAC5BAB1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"4518","Ordinal":"1","Title":"CVE-2015-4518","CVE":"CVE-2015-4518","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"4518","Ordinal":"1","NoteData":"The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors involving SVG animations and the about:reader URL.","Type":"Description","Title":"CVE-2015-4518"},{"CveYear":"2015","CveId":"4518","Ordinal":"2","NoteData":"2015-11-04","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"4518","Ordinal":"3","NoteData":"2016-12-05","Type":"Other","Title":"Modified"}]}}}