← Vulnerability feed

Vulnerability record · CVE-2015-0816 · published 1 April 2015

CVE-2015-0816: Mozilla Firefox and Thunderbird resource: URL Same Origin Policy bypass

Mozilla · Firefox

Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 fail to properly restrict resource: URLs, allowing the Same Origin Policy to be bypassed. This lets remote attackers run arbitrary JavaScript with chrome privileges, as demonstrated via the resource: URL used by PDF.js.

5.0 CVSS 2.0 Medium EPSS 67% · top 0.7% CWE-264 · Permissions and access controls
5.0CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
36References
17 Jun 2026Last modified by NVD

Description

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.

AV:N/AC:L/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw allows chrome-privilege code execution via a Same Origin Policy bypass, public exploit code exists, and EPSS is very high, though the CVSS impact is limited to integrity.

What it is

Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 fail to properly restrict resource: URLs, allowing the Same Origin Policy to be bypassed. This lets remote attackers run arbitrary JavaScript with chrome privileges, as demonstrated via the resource: URL used by PDF.js.

Impact

An attacker can execute arbitrary JavaScript with chrome (browser-internal) privileges, potentially reading or modifying browser data and escalating beyond normal web content permissions.

Attack surface

Reachable remotely over the network with no authentication required, per the CVSS vector AV:N/AC:L/Au:N. The description does not state whether user interaction such as visiting a crafted page or opening a PDF is required.

Exploitation

Not listed in CISA KEV, but EPSS is high at 0.66936 (99.26th percentile) and a public Exploit-DB entry (37958) exists, indicating known exploit code is available.

What to do

  • Upgrade Firefox to 37.0 or later and Firefox ESR to 31.6 or later; upgrade Thunderbird to 31.6 or later.
  • Apply vendor and distribution patches (Mozilla MFSA 2015-33, Red Hat, Debian, Ubuntu, SUSE, Gentoo, Oracle) where the browser cannot be upgraded immediately.
  • Disable or restrict the PDF.js viewer if it cannot be patched, since the demonstrated vector uses its resource: URL.
  • Enforce browser update policies so ESR and Thunderbird installations do not remain on pre-31.6 builds.

Detection

  • Monitor for resource: URL usage in browser or Thunderbird process activity, especially in conjunction with PDF.js.
  • Alert on unexpected JavaScript execution or chrome-privilege errors logged by Firefox or Thunderbird.
  • Track endpoint versions of Firefox, Firefox ESR and Thunderbird and flag any below 37.0 / 31.6.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
http://rhn.redhat.com/errata/RHSA-2015-0766.html
http://rhn.redhat.com/errata/RHSA-2015-0771.html
http://www.debian.org/security/2015/dsa-3211
http://www.debian.org/security/2015/dsa-3212
http://www.mozilla.org/security/announce/2015/mfsa2015-33.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
http://www.securityfocus.com/bid/73461
http://www.securitytracker.com/id/1031996
http://www.securitytracker.com/id/1032000
http://www.ubuntu.com/usn/USN-2550-1
http://www.ubuntu.com/usn/USN-2552-1
https://bugzilla.mozilla.org/show_bug.cgi?id=1144991
https://security.gentoo.org/glsa/201512-10
https://www.exploit-db.com/exploits/37958/
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
http://rhn.redhat.com/errata/RHSA-2015-0766.html
http://rhn.redhat.com/errata/RHSA-2015-0771.html
http://www.debian.org/security/2015/dsa-3211
http://www.debian.org/security/2015/dsa-3212
http://www.mozilla.org/security/announce/2015/mfsa2015-33.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
http://www.securityfocus.com/bid/73461
http://www.securitytracker.com/id/1031996
http://www.securitytracker.com/id/1032000
http://www.ubuntu.com/usn/USN-2550-1
http://www.ubuntu.com/usn/USN-2552-1
https://bugzilla.mozilla.org/show_bug.cgi?id=1144991
https://security.gentoo.org/glsa/201512-10
https://www.exploit-db.com/exploits/37958/

Track CVE-2015-0816 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2019-11708Mozilla Firefox and Thunderbird sandbox escape via Prompt:Open IPC validation flawThe Prompt:Open IPC message between child and parent processes does not sufficiently vet its parameters, letting a compromised child process cause th…KEVEPSS 56%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2010-3765Mozilla Firefox, Thunderbird and SeaMonkey memory corruption via appendChildA memory corruption flaw in Mozilla Firefox, Thunderbird and SeaMonkey arises from incorrect index tracking in nsCSSFrameConstructor::ContentAppended…KEVEPSS 83%analysed9.6CVE-2022-26486Firefox WebGPU IPC use-after-free enables sandbox escapeAn unexpected message in the WebGPU IPC framework triggers a use-after-free in Mozilla Firefox, Firefox ESR, Firefox for Android, Thunderbird and Foc…KEVEPSS 2.3%analysed8.8CVE-2023-5217libvpx VP8 encoding heap buffer overflow exploited via crafted HTMLA heap buffer overflow in the VP8 encoder in libvpx affects Google Chrome before 117.0.5938.132 and libvpx 1.13.1, and is reachable through a crafted…KEVEPSS 49%analysed8.8CVE-2023-4863libwebp Heap Buffer Overflow via Crafted WebP ImageA heap buffer overflow in libwebp allows an out-of-bounds memory write when processing a crafted WebP image. It affects Google Chrome before 116.0.58…KEVEPSS 100%analysed8.8CVE-2022-26485Firefox XSLT parameter removal use-after-freeRemoving an XSLT parameter during processing in Mozilla Firefox could trigger a use-after-free condition. Mozilla reported attacks in the wild abusin…KEVEPSS 14%analysed8.8CVE-2019-17026Firefox and Thunderbird IonMonkey JIT type confusionIncorrect alias information in the IonMonkey JIT compiler when setting array elements can cause a type confusion in Firefox, Firefox ESR and Thunderb…KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2015-0816), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.