Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
Configuration 3 (hide)
| 
 | 
Configuration 4 (hide)
| 
 | 
History
                    21 Nov 2024, 02:36
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174083.html - | |
| References | () http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174253.html - | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00089.html - | |
| References | () http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00091.html - | |
| References | () http://lists.opensuse.org/opensuse-updates/2015-12/msg00104.html - | |
| References | () http://lists.opensuse.org/opensuse-updates/2016-02/msg00007.html - | |
| References | () http://lists.opensuse.org/opensuse-updates/2016-02/msg00008.html - | |
| References | () http://www.mozilla.org/security/announce/2015/mfsa2015-136.html - Vendor Advisory | |
| References | () http://www.securityfocus.com/bid/79280 - | |
| References | () http://www.securitytracker.com/id/1034426 - | |
| References | () http://www.ubuntu.com/usn/USN-2833-1 - | |
| References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1185256 - | |
| References | () https://github.com/w3c/resource-timing/issues/29 - Vendor Advisory | |
| References | () https://security.gentoo.org/glsa/201512-10 - | 
Information
                Published : 2015-12-16 11:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-7207
Mitre link : CVE-2015-7207
CVE.ORG link : CVE-2015-7207
JSON object : View
Products Affected
                opensuse
- opensuse
- leap
mozilla
- firefox
fedoraproject
- fedora
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
