Lucene search

K
cveMozillaCVE-2015-4521
HistorySep 24, 2015 - 4:59 a.m.

CVE-2015-4521

2015-09-2404:59:20
CWE-119
mozilla
web.nvd.nist.gov
58
cve-2015-4521
mozilla firefox
firefox esr
memory corruption
application crash
denial of service

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.3

Confidence

High

EPSS

0.066

Percentile

93.8%

The ConvertDialogOptions function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.

Affected configurations

Nvd
Node
mozillafirefoxRange40.0.3
Node
mozillafirefox_esrMatch38.0
OR
mozillafirefox_esrMatch38.0.1
OR
mozillafirefox_esrMatch38.0.5
OR
mozillafirefox_esrMatch38.1.0
OR
mozillafirefox_esrMatch38.1.1
OR
mozillafirefox_esrMatch38.2.0
OR
mozillafirefox_esrMatch38.2.1
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillafirefox_esr38.0cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:*
mozillafirefox_esr38.0.1cpe:2.3:a:mozilla:firefox_esr:38.0.1:*:*:*:*:*:*:*
mozillafirefox_esr38.0.5cpe:2.3:a:mozilla:firefox_esr:38.0.5:*:*:*:*:*:*:*
mozillafirefox_esr38.1.0cpe:2.3:a:mozilla:firefox_esr:38.1.0:*:*:*:*:*:*:*
mozillafirefox_esr38.1.1cpe:2.3:a:mozilla:firefox_esr:38.1.1:*:*:*:*:*:*:*
mozillafirefox_esr38.2.0cpe:2.3:a:mozilla:firefox_esr:38.2.0:*:*:*:*:*:*:*
mozillafirefox_esr38.2.1cpe:2.3:a:mozilla:firefox_esr:38.2.1:*:*:*:*:*:*:*

References

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.3

Confidence

High

EPSS

0.066

Percentile

93.8%