Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2015-7184
Description:The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user credentials are supplied but the CORS cross-origin request algorithm is improperly followed, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
Test IDs: 1.3.6.1.4.1.25623.1.0.842491   1.3.6.1.4.1.25623.1.2.1.2015.115   1.3.6.1.4.1.25623.1.0.806514   1.3.6.1.4.1.25623.1.0.851119   1.3.6.1.4.1.25623.1.0.806515  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2015-7184
BugTraq ID: 77100
http://www.securityfocus.com/bid/77100
http://www.securitytracker.com/id/1033820
SuSE Security Announcement: openSUSE-SU-2015:1817 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00021.html
http://www.ubuntu.com/usn/USN-2768-1




© 1998-2025 E-Soft Inc. All rights reserved.