Lucene search

K
cveMozillaCVE-2015-7178
HistorySep 24, 2015 - 4:59 a.m.

CVE-2015-7178

2015-09-2404:59:25
CWE-119
mozilla
web.nvd.nist.gov
41
security
vulnerability
cve
angle
libgles
mozilla firefox
windows
remote code execution
denial of service
memory corruption
application crash
opengl
webgl
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

High

EPSS

0.058

Percentile

93.4%

The ProgramBinary::linkAttributes function in libGLES in ANGLE, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows, mishandles shader access, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted (1) OpenGL or (2) WebGL content.

Affected configurations

Nvd
Node
mozillafirefox_esrMatch38.0
OR
mozillafirefox_esrMatch38.0.1
OR
mozillafirefox_esrMatch38.0.5
OR
mozillafirefox_esrMatch38.1.0
OR
mozillafirefox_esrMatch38.1.1
OR
mozillafirefox_esrMatch38.2.0
OR
mozillafirefox_esrMatch38.2.1
AND
microsoftwindows
Node
mozillafirefoxRange40.0.3
AND
microsoftwindows
VendorProductVersionCPE
mozillafirefox_esr38.0cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:*
mozillafirefox_esr38.0.1cpe:2.3:a:mozilla:firefox_esr:38.0.1:*:*:*:*:*:*:*
mozillafirefox_esr38.0.5cpe:2.3:a:mozilla:firefox_esr:38.0.5:*:*:*:*:*:*:*
mozillafirefox_esr38.1.0cpe:2.3:a:mozilla:firefox_esr:38.1.0:*:*:*:*:*:*:*
mozillafirefox_esr38.1.1cpe:2.3:a:mozilla:firefox_esr:38.1.1:*:*:*:*:*:*:*
mozillafirefox_esr38.2.0cpe:2.3:a:mozilla:firefox_esr:38.2.0:*:*:*:*:*:*:*
mozillafirefox_esr38.2.1cpe:2.3:a:mozilla:firefox_esr:38.2.1:*:*:*:*:*:*:*
microsoftwindows*cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

High

EPSS

0.058

Percentile

93.4%