CVE-2015-7186

Publication date 5 November 2015

Last updated 24 July 2024


Ubuntu priority

Description

Mozilla Firefox before 42.0 on Android allows user-assisted remote attackers to bypass the Same Origin Policy and trigger (1) a download or (2) cached profile-data reading via a file: URL in a saved HTML document.

Read the notes from the security team

Status

Package Ubuntu Release Status
firefox 15.10 wily
Not affected
15.04 vivid
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected

Notes


chrisccoulson

Android only


Access our resources on patching vulnerabilities