CVE-2015-7183

EUVD-2015-7115
Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
𝑥
≤ 41.0.2
mozillanetwork_security_services
𝑥
≤ 3.19.2.0
mozillanetwork_security_services
3.20.0
mozillafirefox
38.0
mozillafirefox
38.0.1
mozillafirefox
38.0.5
mozillafirefox
38.1.0
mozillafirefox
38.1.1
mozillafirefox
38.2.0
mozillafirefox
38.2.1
mozillafirefox
38.3.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nspr
bookworm
2:4.35-1
fixed
bullseye
2:4.29-1
fixed
sid
2:4.35-1.1
fixed
trixie
2:4.35-1.1
fixed
wheezy
no-dsa
virtualbox
sid/contrib
7.0.20-dfsg-1
fixed
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
precise
Fixed 42.0+build2-0ubuntu0.12.04.1
released
trusty
Fixed 42.0+build2-0ubuntu0.14.04.1
released
vivid
Fixed 42.0+build2-0ubuntu0.15.04.1
released
wily
Fixed 42.0+build2-0ubuntu0.15.10.1
released
xenial
Fixed 42.0+build2-0ubuntu1
released
yakkety
Fixed 42.0+build2-0ubuntu1
released
zesty
Fixed 42.0+build2-0ubuntu1
released
nspr
precise
Fixed 4.10.10-0ubuntu0.12.04.1
released
trusty
Fixed 2:4.10.10-0ubuntu0.14.04.1
released
vivid
Fixed 2:4.10.10-0ubuntu0.15.04.1
released
wily
Fixed 2:4.10.10-0ubuntu0.15.10.1
released
xenial
not-affected
yakkety
not-affected
zesty
not-affected
thunderbird
precise
Fixed 1:38.4.0+build3-0ubuntu0.12.04.1
released
trusty
Fixed 1:38.4.0+build3-0ubuntu0.14.04.1
released
vivid
Fixed 1:38.4.0+build3-0ubuntu0.15.04.1
released
wily
Fixed 1:38.4.0+build3-0ubuntu0.15.10.1
released
xenial
Fixed 1:38.4.0+build3-0ubuntu1
released
yakkety
Fixed 1:38.4.0+build3-0ubuntu1
released
zesty
Fixed 1:38.4.0+build3-0ubuntu1
released
virtualbox
precise
ignored
trusty
Fixed 4.3.36-dfsg-1+deb8u1ubuntu1.14.04.1
released
vivid
Fixed 4.3.36-dfsg-1+deb8u1ubuntu1.15.04.1
released
wily
Fixed 5.0.14-dfsg-0ubuntu1.15.10.1
released
xenial
not-affected
yakkety
not-affected
zesty
not-affected
References