Search/CVE-2015-7204
CVE

CVE-2015-7204

Mozilla Firefox before 43.0 does not properly store the properties of unboxed objects, which allows remote attackers to execute arbitrary code via crafted JavaScript variable assignments.

CVSS v3.1
EPSS
3.49%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Connections
5 relationships
Timeline
disclosure → media coverage
Dec 16, 2015
Disclosure — published as a CVE record. · last revised by NVD May 6, 2026