Lucene search

K
cve[email protected]CVE-2015-2716
HistoryMay 14, 2015 - 10:59 a.m.

CVE-2015-2716

2015-05-1410:59:09
CWE-119
web.nvd.nist.gov
337
3
cve-2015-2716
buffer overflow
mozilla firefox
xml parser
code execution
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.6 High

AI Score

Confidence

High

0.033 Low

EPSS

Percentile

91.3%

Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.

Affected configurations

NVD
Node
mozillafirefoxRange37.0.2
Node
novellsuse_linux_enterprise_software_development_kitMatch12.0
OR
novellsuse_linux_enterprise_desktopMatch12.0
OR
novellsuse_linux_enterprise_serverMatch12.0
OR
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2
Node
mozillathunderbirdRange31.5
Node
oraclesolarisMatch11.3
Node
mozillafirefox_esrMatch31.0
OR
mozillafirefox_esrMatch31.1
OR
mozillafirefox_esrMatch31.1.0
OR
mozillafirefox_esrMatch31.1.1
OR
mozillafirefox_esrMatch31.2
OR
mozillafirefox_esrMatch31.3
OR
mozillafirefox_esrMatch31.3.0
OR
mozillafirefox_esrMatch31.4
OR
mozillafirefox_esrMatch31.5
OR
mozillafirefox_esrMatch31.5.1
OR
mozillafirefox_esrMatch31.5.2
OR
mozillafirefox_esrMatch31.5.3
OR
mozillafirefox_esrMatch31.6.0
CPENameOperatorVersion
mozilla:firefoxmozilla firefoxle37.0.2

References

Social References

More

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.6 High

AI Score

Confidence

High

0.033 Low

EPSS

Percentile

91.3%