Lucene search

K
cve[email protected]CVE-2015-7216
HistoryDec 16, 2015 - 11:59 a.m.

CVE-2015-7216

2015-12-1611:59:14
CWE-20
web.nvd.nist.gov
48
cve-2015-7216
mozilla firefox
linux
gnome
jasper decoder
denial of service
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

High

EPSS

0.028

Percentile

90.7%

The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JPEG 2000 image.

Affected configurations

NVD
Node
fedoraprojectfedoraMatch22
OR
fedoraprojectfedoraMatch23
Node
mozillafirefoxRange42.0
AND
gnomegnomeMatch-linux
Node
opensuseleapMatch42.1
OR
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2
VendorProductVersionCPE
fedoraprojectfedora23cpe:/o:fedoraproject:fedora:23:::
fedoraprojectfedora22cpe:/o:fedoraproject:fedora:22:::

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

High

EPSS

0.028

Percentile

90.7%