← Back

CVE-2015-2736

nvd nist
Published: Jul 6, 2015Modified: May 6, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.

Affected (28)

Show all products
3 products
Firefox
Thunderbird
Firefox Esr
1 product
Solaris
1 product
Ubuntu Linux
1 product
Debian Linux
3 products
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 38.1.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 38.0.1
Configuration C
15 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 31.0
Version 31.1.0
Version 31.1.1
Version 31.3.0
Version 31.5.1
Version 31.5.2
Version 31.5.3
Version 38.0
Mozilla
Version 31.1
Version 31.2
Version 31.3
Version 31.4
Version 31.5
Version 31.6.0
Version 31.7.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.3
Configuration E
10 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 14.10
Version 15.04
Debian
Version 7.0
Version 8.0
Version 12.0
Novell
Version 11 sp4
Version 12.0
Version 12.0

Related CWEs

References (40)

Source: security@mozilla.org
Third Party Advisory
Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Third Party Advisory
Source: security@mozilla.org
Issue Tracking
Source: security@mozilla.org
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.