CVE-2015-2726
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.06%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 6.06% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- oracle/solaris · mozilla/firefox · novell/suse linux enterprise software development kit · novell/suse linux enterprise desktop · novell/suse linux enterprise server
- Source
- security@mozilla.org
References
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00033.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00034.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-59.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlThird Party Advisory
- http://www.securityfocus.com/bid/75541
- http://www.securitytracker.com/id/1032783
- http://www.securitytracker.com/id/1032784
- http://www.ubuntu.com/usn/USN-2656-1
- http://www.ubuntu.com/usn/USN-2656-2
- https://bugzilla.mozilla.org/show_bug.cgi?id=1059081Issue Tracking
- https://bugzilla.mozilla.org/show_bug.cgi?id=1132265Issue Tracking, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1145781Issue Tracking, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1146416Issue Tracking, Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1155985Issue Tracking, Vendor Advisory
- https://security.gentoo.org/glsa/201512-10
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00033.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00034.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.html
- http://www.mozilla.org/security/announce/2015/mfsa2015-59.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlThird Party Advisory
- http://www.securityfocus.com/bid/75541
- http://www.securitytracker.com/id/1032783
- http://www.securitytracker.com/id/1032784
- http://www.ubuntu.com/usn/USN-2656-1
- http://www.ubuntu.com/usn/USN-2656-2
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.