{"api_version":"1","generated_at":"2026-07-23T12:02:45+00:00","cve":"CVE-2015-7207","urls":{"html":"https://cve.report/CVE-2015-7207","api":"https://cve.report/api/cve/CVE-2015-7207.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-7207","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-7207"},"summary":{"title":"CVE-2015-7207","description":"Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.","state":"PUBLISHED","assigner":"mozilla","published_at":"2015-12-16 11:59:06","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174253.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174253.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] Fedora 22 Update: firefox-43.0-1.fc22","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00091.html","name":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00091.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] openSUSE-SU-2016:0894-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/79280","name":"http://www.securityfocus.com/bid/79280","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mozilla Firefox Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://lists.opensuse.org/opensuse-updates/2015-12/msg00104.html","name":"http://lists.opensuse.org/opensuse-updates/2015-12/msg00104.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"openSUSE-SU-2015:2353-1: moderate: Security update for MozillaFirefox","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00008.html","name":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00008.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"openSUSE-SU-2016:0308-1: moderate: Security update for Seamonkey","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174083.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174083.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] Fedora 23 Update: firefox-43.0-1.fc23","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00089.html","name":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00089.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] openSUSE-SU-2016:0876-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00007.html","name":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00007.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"openSUSE-SU-2016:0307-1: moderate: Security update for seamonkey","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1185256","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1185256","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"1185256 - (CVE-2015-7207) performance.getEntries() shows x-domain URLs after a redirect when loading from cache","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2015/mfsa2015-136.html","name":"http://www.mozilla.org/security/announce/2015/mfsa2015-136.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Same-origin policy violation using performance.getEntries and history navigation — Mozilla","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-2833-1","name":"http://www.ubuntu.com/usn/USN-2833-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-2833-1: Firefox vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/w3c/resource-timing/issues/29","name":"https://github.com/w3c/resource-timing/issues/29","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cached redirects + History traversal reveal cross-origin URLs · Issue #29 · w3c/resource-timing · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201512-10","name":"https://security.gentoo.org/glsa/201512-10","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mozilla Products: Multiple vulnerabilities  (GLSA 201512-10) — Gentoo Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1034426","name":"http://www.securitytracker.com/id/1034426","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Obtain Potentially Sensitive Information, Bypass Same-Origin Policy, and Cause Denial of Service Conditions - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-7207","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-7207","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"7207","vulnerable":"1","versionEndIncluding":"42.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7207","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"leap","cpe6":"42.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7207","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"opensuse","cpe6":"13.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7207","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"opensuse","cpe6":"13.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T07:43:45.652Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"openSUSE-SU-2016:0894","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00091.html"},{"name":"GLSA-201512-10","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201512-10"},{"name":"openSUSE-SU-2015:2353","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2015-12/msg00104.html"},{"name":"openSUSE-SU-2016:0876","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00089.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1185256"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/w3c/resource-timing/issues/29"},{"name":"openSUSE-SU-2016:0308","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00008.html"},{"name":"FEDORA-2015-7ab3d3afcf","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174253.html"},{"name":"USN-2833-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2833-1"},{"name":"79280","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/79280"},{"name":"openSUSE-SU-2016:0307","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00007.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/2015/mfsa2015-136.html"},{"name":"FEDORA-2015-51b1105902","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174083.html"},{"name":"1034426","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1034426"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-12-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-05T20:57:01.000Z","orgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","shortName":"mozilla"},"references":[{"name":"openSUSE-SU-2016:0894","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00091.html"},{"name":"GLSA-201512-10","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201512-10"},{"name":"openSUSE-SU-2015:2353","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2015-12/msg00104.html"},{"name":"openSUSE-SU-2016:0876","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00089.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1185256"},{"tags":["x_refsource_MISC"],"url":"https://github.com/w3c/resource-timing/issues/29"},{"name":"openSUSE-SU-2016:0308","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00008.html"},{"name":"FEDORA-2015-7ab3d3afcf","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174253.html"},{"name":"USN-2833-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2833-1"},{"name":"79280","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/79280"},{"name":"openSUSE-SU-2016:0307","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00007.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/2015/mfsa2015-136.html"},{"name":"FEDORA-2015-51b1105902","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174083.html"},{"name":"1034426","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1034426"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@mozilla.org","ID":"CVE-2015-7207","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"openSUSE-SU-2016:0894","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00091.html"},{"name":"GLSA-201512-10","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201512-10"},{"name":"openSUSE-SU-2015:2353","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2015-12/msg00104.html"},{"name":"openSUSE-SU-2016:0876","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00089.html"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1185256","refsource":"CONFIRM","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1185256"},{"name":"https://github.com/w3c/resource-timing/issues/29","refsource":"MISC","url":"https://github.com/w3c/resource-timing/issues/29"},{"name":"openSUSE-SU-2016:0308","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00008.html"},{"name":"FEDORA-2015-7ab3d3afcf","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174253.html"},{"name":"USN-2833-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2833-1"},{"name":"79280","refsource":"BID","url":"http://www.securityfocus.com/bid/79280"},{"name":"openSUSE-SU-2016:0307","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2016-02/msg00007.html"},{"name":"http://www.mozilla.org/security/announce/2015/mfsa2015-136.html","refsource":"CONFIRM","url":"http://www.mozilla.org/security/announce/2015/mfsa2015-136.html"},{"name":"FEDORA-2015-51b1105902","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174083.html"},{"name":"1034426","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1034426"}]}}}},"cveMetadata":{"assignerOrgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","assignerShortName":"mozilla","cveId":"CVE-2015-7207","datePublished":"2015-12-16T11:00:00.000Z","dateReserved":"2015-09-16T00:00:00.000Z","dateUpdated":"2024-08-06T07:43:45.652Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-12-16 11:59:06","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionEndIncluding":"42.0","matchCriteriaId":"735317AD-14B8-4A73-B5B0-6A4C84FC202E"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*","matchCriteriaId":"4863BE36-D16A-4D75-90D9-FD76DB5B48B7"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*","matchCriteriaId":"A10BC294-9196-425F-9FB0-B1625465B47F"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*","matchCriteriaId":"03117DF1-3BEC-4B8D-AD63-DBBDB2126081"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*","matchCriteriaId":"A10BC294-9196-425F-9FB0-B1625465B47F"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*","matchCriteriaId":"253C303A-E577-4488-93E6-68A8DD942C38"},{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*","matchCriteriaId":"E79AB8DD-C907-4038-A931-1A5A4CFB6A5B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"7207","Ordinal":"1","Title":"CVE-2015-7207","CVE":"CVE-2015-7207","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"7207","Ordinal":"1","NoteData":"Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.","Type":"Description","Title":"CVE-2015-7207"},{"CveYear":"2015","CveId":"7207","Ordinal":"2","NoteData":"2015-12-16","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"7207","Ordinal":"3","NoteData":"2016-12-05","Type":"Other","Title":"Modified"}]}}}