CVE-2015-2738

The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
mozillaCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
VendorProductVersion
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
14.10
canonicalubuntu_linux
15.04
debiandebian_linux
7.0
debiandebian_linux
8.0
mozillafirefox
𝑥
≤ 38.1.0
mozillafirefox
31.0
mozillafirefox
31.1.0
mozillafirefox
31.1.1
mozillafirefox
31.3.0
mozillafirefox
31.5.1
mozillafirefox
31.5.2
mozillafirefox
31.5.3
mozillafirefox
38.0
mozillafirefox_esr
31.1
mozillafirefox_esr
31.2
mozillafirefox_esr
31.3
mozillafirefox_esr
31.4
mozillafirefox_esr
31.5
mozillafirefox_esr
31.6.0
mozillafirefox_esr
31.7.0
mozillathunderbird
𝑥
≤ 38.0.1
oraclesolaris
11.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
vivid
Fixed 39.0+build5-0ubuntu0.15.04.1
released
utopic
Fixed 39.0+build5-0ubuntu0.14.10.1
released
trusty
Fixed 39.0+build5-0ubuntu0.14.04.1
released
precise
Fixed 39.0+build5-0ubuntu0.12.04.2
released
thunderbird
vivid
Fixed 1:31.8.0+build1-0ubuntu0.15.04.1
released
utopic
Fixed 1:31.8.0+build1-0ubuntu0.14.10.1
released
trusty
Fixed 1:31.8.0+build1-0ubuntu0.14.04.1
released
precise
Fixed 1:31.8.0+build1-0ubuntu0.12.04.1
released
Common Weakness Enumeration
References