AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2015-0802

MEDIUM · CVSS 5 EPSS 67.27% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-04-01 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2015-0802
Severity
MEDIUM
CVSS
5
EPSS
67.27%
Chrome Firefox Java

Original Filing — NVD Description

Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content navigation that leverages the reachability of a privileged window with an unintended persistence of access to restricted internal methods.