CVE-2015-4509

EUVD-2015-4529
Use-after-free vulnerability in the HTMLVideoElement interface in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via crafted JavaScript code that modifies the URI table of a media element, aka ZDI-CAN-3176.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
38.0
mozillafirefox
38.0.1
mozillafirefox
38.0.5
mozillafirefox
38.1.0
mozillafirefox
38.1.1
mozillafirefox
38.2.0
mozillafirefox
38.2.1
mozillafirefox
𝑥
≤ 40.0.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
precise
Fixed 41.0+build3-0ubuntu0.12.04.1
released
trusty
Fixed 41.0+build3-0ubuntu0.14.04.1
released
vivid
Fixed 41.0+build3-0ubuntu0.15.04.1
released
thunderbird
precise
Fixed 1:38.3.0+build1-0ubuntu0.12.04.1
released
trusty
Fixed 1:38.3.0+build1-0ubuntu0.14.04.1
released
vivid
Fixed 1:38.3.0+build1-0ubuntu0.15.04.1
released
References