Lucene search

K
cveMozillaCVE-2015-2729
HistoryJul 06, 2015 - 2:01 a.m.

CVE-2015-2729

2015-07-0602:01:00
CWE-119
mozilla
web.nvd.nist.gov
56
cve-2015-2729
audioparamtimeline
audionodeinputvalue
web audio
mozilla firefox
denial of service
out-of-bounds read
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

4.2

Confidence

High

EPSS

0.004

Percentile

74.8%

The AudioParamTimeline::AudioNodeInputValue function in the Web Audio implementation in Mozilla Firefox before 39.0 and Firefox ESR 38.x before 38.1 does not properly calculate an oscillator rendering range, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspecified vectors.

Affected configurations

Nvd
Node
mozillafirefox_esrMatch31.0
OR
mozillafirefox_esrMatch31.1
OR
mozillafirefox_esrMatch31.1.0
OR
mozillafirefox_esrMatch31.1.1
OR
mozillafirefox_esrMatch31.2
OR
mozillafirefox_esrMatch31.3
OR
mozillafirefox_esrMatch31.3.0
OR
mozillafirefox_esrMatch31.4
OR
mozillafirefox_esrMatch31.5
OR
mozillafirefox_esrMatch31.5.1
OR
mozillafirefox_esrMatch31.5.2
OR
mozillafirefox_esrMatch31.5.3
OR
mozillafirefox_esrMatch31.6.0
OR
mozillafirefox_esrMatch31.7.0
OR
mozillafirefox_esrMatch38.0
Node
mozillathunderbirdRange38.0.1
Node
mozillafirefoxRange38.1.0
Node
oraclesolarisMatch11.3
VendorProductVersionCPE
mozillafirefox_esr31.5cpe:/a:mozilla:firefox_esr:31.5:::
mozillafirefox_esr31.1cpe:/a:mozilla:firefox_esr:31.1:::
mozillafirefox_esr31.5.2cpe:/a:mozilla:firefox_esr:31.5.2:::
mozillafirefox_esr31.3.0cpe:/a:mozilla:firefox_esr:31.3.0:::
mozillafirefox_esr31.6.0cpe:/a:mozilla:firefox_esr:31.6.0:::
mozillafirefox_esr31.4cpe:/a:mozilla:firefox_esr:31.4:::
mozillafirefox_esr31.3cpe:/a:mozilla:firefox_esr:31.3:::
mozillafirefox_esr31.1.0cpe:/a:mozilla:firefox_esr:31.1.0:::
mozillafirefox_esr31.0cpe:/a:mozilla:firefox_esr:31.0:::
mozillafirefox_esr31.5.1cpe:/a:mozilla:firefox_esr:31.5.1:::
Rows per page:
1-10 of 151

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

4.2

Confidence

High

EPSS

0.004

Percentile

74.8%