MEDIUM · 4.0

CVE-2015-7223

The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted w...

Vulnerability Description

The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted web site.

CVSS Score

4.0

MEDIUM

AV:N/AC:H/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
FedoraprojectFedora22
MozillaFirefox<= 42.0
OpensuseLeap42.1
OpensuseOpensuse13.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-7223?

CVE-2015-7223 is a vulnerability with a CVSS score of 4.0 (MEDIUM). The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted w...

How severe is CVE-2015-7223?

CVE-2015-7223 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-7223?

Check the references section above for vendor advisories and patch information. Affected products include: Fedoraproject Fedora, Mozilla Firefox, Opensuse Leap, Opensuse Opensuse.