← Back

CVE-2015-2729

nvd nist
Published: Jul 6, 2015Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The AudioParamTimeline::AudioNodeInputValue function in the Web Audio implementation in Mozilla Firefox before 39.0 and Firefox ESR 38.x before 38.1 does not properly calculate an oscillator rendering range, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspecified vectors.

Affected (18)

3 products
Firefox
Firefox Esr
Thunderbird
1 product
Solaris
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 31.0
Version 31.1.0
Version 31.1.1
Version 31.3.0
Version 31.5.1
Version 31.5.2
Version 31.5.3
Version 38.0
Mozilla
Version 31.1
Version 31.2
Version 31.3
Version 31.4
Version 31.5
Version 31.6.0
Version 31.7.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 38.0.1
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 38.1.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.3

References (22)

Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Issue Tracking
Source: security@mozilla.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.