A critical vulnerability in the PDF reader component of Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy. By leveraging crafted JavaScript code and a native setter, attackers can read arbitrary files or escalate privileges. This vulnerability was actively exploited in the wild in August 2015.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit auxiliary module: 'firefox_pdfjs_file_theft.rb'. The module exploits CVE-2015-4495, an XSS vulnerability in the PDF.js component of Firefox (prior to 39.0.3), Firefox ESR (prior to 38.1.1), and Firefox OS 2.2. When a victim visits a malicious web server hosting the exploit, JavaScript is used to abuse PDF.js's privileges to read arbitrary files from the victim's filesystem. The files are then exfiltrated via HTTP POST requests to the attacker's server. The module allows the attacker to specify which files to target (defaulting to '/etc/passwd' and '/etc/shadow'). The exploit is operational and leverages both Ruby (for the Metasploit module) and JavaScript (for the browser payload). The attack vector is browser-based, requiring user interaction (visiting the malicious site). The module is not a detection script but a functional exploit for file theft via a browser vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.