← Back

CVE-2015-2716

nvd nist
Published: May 14, 2015Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.

Affected (21)

Show all products
3 products
Firefox
Thunderbird
Firefox Esr
3 products
1 product
Opensuse
1 product
Solaris
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 37.0.2
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.0
Version 12.0
Version 12.0
Opensuse
Version 13.1
Version 13.2
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 31.5
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.3
Configuration E
13 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 31.0
Version 31.1.0
Version 31.1.1
Version 31.3.0
Version 31.5.1
Version 31.5.2
Version 31.5.3
Mozilla
Version 31.1
Version 31.2
Version 31.3
Version 31.4
Version 31.5
Version 31.6.0

References (40)

Source: security@mozilla.org
Third Party Advisory
Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Issue Tracking
Source: security@mozilla.org
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.