CVE-2015-2740

Published Jul 6, 2015

Last updated 19 days ago

Overview

Description
Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote attackers to cause a denial of service or have unspecified other impact via unknown vectors.
Source
security@mozilla.org
NVD status
Modified
Products
thunderbird, firefox, firefox_esr, suse_linux_enterprise_software_development_kit, ubuntu_linux, debian_linux, suse_linux_enterprise_desktop, suse_linux_enterprise_server, solaris

Risk scores

CVSS 2.0

Type
Primary
Base score
10
Impact score
10
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

nvd@nist.gov
CWE-119

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.