CVE-2015-7199
05.11.2015, 05:59
The (1) AddWeightedPathSegLists and (2) SVGPathSegListSMILType::Interpolate functions in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 lack status checking, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted SVG document.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mozilla | firefox | 𝑥 ≤ 41.0.2 |
| mozilla | firefox | 38.0 |
| mozilla | firefox | 38.0.1 |
| mozilla | firefox | 38.0.5 |
| mozilla | firefox | 38.1.0 |
| mozilla | firefox | 38.1.1 |
| mozilla | firefox | 38.2.0 |
| mozilla | firefox | 38.2.1 |
| mozilla | firefox | 38.3.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| firefox |
| ||||||||
| thunderbird |
|
Common Weakness Enumeration
References