Your system may not meet the requirements for Firefox, but you can try one of these versions:

Your system doesn't meet the requirements to run Firefox.

Your system doesn't meet the requirements to run Firefox.

Please follow these instructions to install Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2015-78

Same origin violation and local file stealing via PDF reader

Announced
August 6, 2015
Reporter
Cody Crews
Impact
Critical
Products
Firefox, Firefox ESR, Firefox OS
Fixed in
  • Firefox 39.0.3
  • Firefox ESR 38.1.1
  • Firefox OS 2.2

Description

Security researcher Cody Crews reported on a way to violate the same origin policy and inject script into a non-privileged part of the built-in PDF Viewer. This would allow an attacker to read and steal sensitive local files on the victim's computer.

Mozilla has received reports that an exploit based on this vulnerability has been found in the wild.

References