Lucene search

K
cveMozillaCVE-2015-0803
HistoryApr 01, 2015 - 10:59 a.m.

CVE-2015-0803

2015-04-0110:59:04
CWE-264
mozilla
web.nvd.nist.gov
49
cve-2015-0803
htmlsourceelement
remote attack
code execution
denial of service
mozilla firefox

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.3

Confidence

High

EPSS

0.038

Percentile

91.9%

The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element’s attributes, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document.

Affected configurations

Nvd
Node
canonicalubuntu_linuxMatch12.04lts
OR
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch14.10
Node
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2
Node
mozillafirefoxRange36.0.4
VendorProductVersionCPE
canonicalubuntu_linux12.04cpe:/o:canonical:ubuntu_linux:12.04::lts:
canonicalubuntu_linux14.04cpe:/o:canonical:ubuntu_linux:14.04::lts:
canonicalubuntu_linux14.10cpe:/o:canonical:ubuntu_linux:14.10:::

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

9.3

Confidence

High

EPSS

0.038

Percentile

91.9%