CVE-2015-2710

Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code via crafted SVG graphics data in conjunction with a crafted Cascading Style Sheets (CSS) token sequence.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mozillaCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
mozillathunderbird
𝑥
≤ 31.5
mozillafirefox
31.0
mozillafirefox
31.1.0
mozillafirefox
31.1.1
mozillafirefox
31.3.0
mozillafirefox
31.5.1
mozillafirefox
31.5.2
mozillafirefox
31.5.3
mozillafirefox_esr
31.1
mozillafirefox_esr
31.2
mozillafirefox_esr
31.3
mozillafirefox_esr
31.4
mozillafirefox_esr
31.5
mozillafirefox_esr
31.6.0
novellsuse_linux_enterprise_software_development_kit
12.0
novellsuse_linux_enterprise_desktop
12.0
novellsuse_linux_enterprise_server
12.0
opensuseopensuse
13.1
opensuseopensuse
13.2
mozillafirefox
𝑥
≤ 37.0.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
vivid
Fixed 38.0+build3-0ubuntu0.15.04.1
released
utopic
Fixed 38.0+build3-0ubuntu0.14.10.1
released
trusty
Fixed 38.0+build3-0ubuntu0.14.04.1
released
precise
Fixed 38.0+build3-0ubuntu0.12.04.1
released
thunderbird
vivid
Fixed 1:31.7.0+build1-0ubuntu0.15.04.1
released
utopic
Fixed 1:31.7.0+build1-0ubuntu0.14.10.1
released
trusty
Fixed 1:31.7.0+build1-0ubuntu0.14.04.1
released
precise
Fixed 1:31.7.0+build1-0ubuntu0.12.04.1
released
References