CVE-2015-7200

EUVD-2015-7132
The CryptoKey interface implementation in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 lacks status checking, which allows attackers to have an unspecified impact via vectors related to a cryptographic key.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
𝑥
≤ 41.0.2
mozillafirefox
38.0
mozillafirefox
38.0.1
mozillafirefox
38.0.5
mozillafirefox
38.1.0
mozillafirefox
38.1.1
mozillafirefox
38.2.0
mozillafirefox
38.2.1
mozillafirefox
38.3.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
precise
Fixed 42.0+build2-0ubuntu0.12.04.1
released
trusty
Fixed 42.0+build2-0ubuntu0.14.04.1
released
vivid
Fixed 42.0+build2-0ubuntu0.15.04.1
released
wily
Fixed 42.0+build2-0ubuntu0.15.10.1
released
thunderbird
precise
Fixed 1:38.4.0+build3-0ubuntu0.12.04.1
released
trusty
Fixed 1:38.4.0+build3-0ubuntu0.14.04.1
released
vivid
Fixed 1:38.4.0+build3-0ubuntu0.15.04.1
released
wily
Fixed 1:38.4.0+build3-0ubuntu0.15.10.1
released
Common Weakness Enumeration
References