CVE-2015-4488

EUVD-2015-4508
Use-after-free vulnerability in the StyleAnimationValue class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 allows remote attackers to have an unspecified impact by leveraging a StyleAnimationValue::operator self assignment.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
Affected Products (NVD)
VendorProductVersion
oraclesolaris
11.3
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
15.04
opensuseopensuse
13.1
opensuseopensuse
13.2
mozillafirefox
𝑥
≤ 39.0.3
mozillafirefox
38.0
mozillafirefox
38.0.1
mozillafirefox
38.0.5
mozillafirefox
38.1.0
mozillafirefox_os
2.1.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
precise
Fixed 40.0+build4-0ubuntu0.12.04.1
released
trusty
Fixed 40.0+build4-0ubuntu0.14.04.1
released
vivid
Fixed 40.0+build4-0ubuntu0.15.04.1
released
thunderbird
precise
Fixed 1:38.2.0+build1-0ubuntu0.12.04.2
released
trusty
Fixed 1:38.2.0+build1-0ubuntu0.14.04.1
released
vivid
Fixed 1:38.2.0+build1-0ubuntu0.15.04.1
released
References