CVE-2015-2710

EUVD-2015-2800
Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code via crafted SVG graphics data in conjunction with a crafted Cascading Style Sheets (CSS) token sequence.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
Affected Products (NVD)
VendorProductVersion
mozillathunderbird
𝑥
≤ 31.5
mozillafirefox
31.0
mozillafirefox
31.1.0
mozillafirefox
31.1.1
mozillafirefox
31.3.0
mozillafirefox
31.5.1
mozillafirefox
31.5.2
mozillafirefox
31.5.3
mozillafirefox_esr
31.1
mozillafirefox_esr
31.2
mozillafirefox_esr
31.3
mozillafirefox_esr
31.4
mozillafirefox_esr
31.5
mozillafirefox_esr
31.6.0
novellsuse_linux_enterprise_software_development_kit
12.0
novellsuse_linux_enterprise_desktop
12.0
novellsuse_linux_enterprise_server
12.0
opensuseopensuse
13.1
opensuseopensuse
13.2
mozillafirefox
𝑥
≤ 37.0.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
precise
Fixed 38.0+build3-0ubuntu0.12.04.1
released
trusty
Fixed 38.0+build3-0ubuntu0.14.04.1
released
utopic
Fixed 38.0+build3-0ubuntu0.14.10.1
released
vivid
Fixed 38.0+build3-0ubuntu0.15.04.1
released
thunderbird
precise
Fixed 1:31.7.0+build1-0ubuntu0.12.04.1
released
trusty
Fixed 1:31.7.0+build1-0ubuntu0.14.04.1
released
utopic
Fixed 1:31.7.0+build1-0ubuntu0.14.10.1
released
vivid
Fixed 1:31.7.0+build1-0ubuntu0.15.04.1
released
References