CVE-2015-0803
01.04.2015, 10:59
The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document.Enginsight
| Vendor | Product | Version |
|---|---|---|
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 14.10 |
| opensuse | opensuse | 13.1 |
| opensuse | opensuse | 13.2 |
| mozilla | firefox | 𝑥 ≤ 36.0.4 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References