CVE
- Id
- 84470
- CVE No.
- CVE-2015-7193
- Status
- Candidate
- Description
- Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly follow the CORS cross-origin request algorithm for the POST method in situations involving an unspecified Content-Type header manipulation, which allows remote attackers to bypass the Same Origin Policy by leveraging the lack of a preflight-request step.
- Phase
- Assigned (20150916)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
748300 | 84470 | CVE-2015-7193 | CONFIRM:http://www.mozilla.org/security/announce/2015/mfsa2015-127.html | View |
748301 | 84470 | CVE-2015-7193 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=1210302 | View |
748302 | 84470 | CVE-2015-7193 | CONFIRM:http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html | View |
748303 | 84470 | CVE-2015-7193 | CONFIRM:http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html | View |
748304 | 84470 | CVE-2015-7193 | DEBIAN:DSA-3410 | View |
748305 | 84470 | CVE-2015-7193 | URL:http://www.debian.org/security/2015/dsa-3410 | View |
748306 | 84470 | CVE-2015-7193 | DEBIAN:DSA-3393 | View |
748307 | 84470 | CVE-2015-7193 | URL:http://www.debian.org/security/2015/dsa-3393 | View |
748308 | 84470 | CVE-2015-7193 | GENTOO:GLSA-201512-10 | View |
748309 | 84470 | CVE-2015-7193 | URL:https://security.gentoo.org/glsa/201512-10 | View |
748310 | 84470 | CVE-2015-7193 | REDHAT:RHSA-2015:2519 | View |
748311 | 84470 | CVE-2015-7193 | URL:http://rhn.redhat.com/errata/RHSA-2015-2519.html | View |
748312 | 84470 | CVE-2015-7193 | REDHAT:RHSA-2015:1982 | View |
748313 | 84470 | CVE-2015-7193 | URL:http://rhn.redhat.com/errata/RHSA-2015-1982.html | View |
748314 | 84470 | CVE-2015-7193 | SUSE:openSUSE-SU-2015:2229 | View |
748315 | 84470 | CVE-2015-7193 | URL:http://lists.opensuse.org/opensuse-updates/2015-12/msg00037.html | View |
748316 | 84470 | CVE-2015-7193 | SUSE:openSUSE-SU-2015:2245 | View |
748317 | 84470 | CVE-2015-7193 | URL:http://lists.opensuse.org/opensuse-updates/2015-12/msg00049.html | View |
748318 | 84470 | CVE-2015-7193 | SUSE:SUSE-SU-2015:1926 | View |
748319 | 84470 | CVE-2015-7193 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.html | View |
748320 | 84470 | CVE-2015-7193 | SUSE:openSUSE-SU-2015:1942 | View |
748321 | 84470 | CVE-2015-7193 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.html | View |
748322 | 84470 | CVE-2015-7193 | SUSE:SUSE-SU-2015:1978 | View |
748323 | 84470 | CVE-2015-7193 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.html | View |
748324 | 84470 | CVE-2015-7193 | SUSE:SUSE-SU-2015:1981 | View |
748325 | 84470 | CVE-2015-7193 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.html | View |
748326 | 84470 | CVE-2015-7193 | SUSE:SUSE-SU-2015:2081 | View |
748327 | 84470 | CVE-2015-7193 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html | View |
748328 | 84470 | CVE-2015-7193 | UBUNTU:USN-2819-1 | View |
748329 | 84470 | CVE-2015-7193 | URL:http://www.ubuntu.com/usn/USN-2819-1 | View |
748330 | 84470 | CVE-2015-7193 | UBUNTU:USN-2785-1 | View |
748331 | 84470 | CVE-2015-7193 | URL:http://www.ubuntu.com/usn/USN-2785-1 | View |
748332 | 84470 | CVE-2015-7193 | BID:77411 | View |
748333 | 84470 | CVE-2015-7193 | URL:http://www.securityfocus.com/bid/77411 | View |
748334 | 84470 | CVE-2015-7193 | SECTRACK:1034069 | View |