CVE-2015-2739

EUVD-2015-2829
The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which has unspecified impact and attack vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
𝑥
≤ 38.1.0
novellsuse_linux_enterprise_software_development_kit
12.0
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
14.10
canonicalubuntu_linux
15.04
novellsuse_linux_enterprise_desktop
12.0
novellsuse_linux_enterprise_server
12.0
debiandebian_linux
7.0
debiandebian_linux
8.0
mozillafirefox
31.0
mozillafirefox
31.1.0
mozillafirefox
31.1.1
mozillafirefox
31.3.0
mozillafirefox
31.5.1
mozillafirefox
31.5.2
mozillafirefox
31.5.3
mozillafirefox
38.0
mozillafirefox_esr
31.1
mozillafirefox_esr
31.2
mozillafirefox_esr
31.3
mozillafirefox_esr
31.4
mozillafirefox_esr
31.5
mozillafirefox_esr
31.6.0
mozillafirefox_esr
31.7.0
oraclesolaris
11.3
mozillathunderbird
𝑥
≤ 38.0.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
precise
Fixed 39.0+build5-0ubuntu0.12.04.2
released
trusty
Fixed 39.0+build5-0ubuntu0.14.04.1
released
utopic
Fixed 39.0+build5-0ubuntu0.14.10.1
released
vivid
Fixed 39.0+build5-0ubuntu0.15.04.1
released
thunderbird
precise
Fixed 1:31.8.0+build1-0ubuntu0.12.04.1
released
trusty
Fixed 1:31.8.0+build1-0ubuntu0.14.04.1
released
utopic
Fixed 1:31.8.0+build1-0ubuntu0.14.10.1
released
vivid
Fixed 1:31.8.0+build1-0ubuntu0.15.04.1
released
References