Lucene search

K
kasperskyKaspersky LabKLA10477
HistoryMar 20, 2015 - 12:00 a.m.

KLA10477 Multiple vulnerabilities in Mozilla Firefox and Firefox ESR

2015-03-2000:00:00
Kaspersky Lab
threats.kaspersky.com
30

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.201

Percentile

96.4%

An unspecified vulnerability was found in Mozilla products. By exploiting this vulnerability malicious users execute arbitrary code or gain privileges. This vulnerability can be exploited remotely via a SVG navigation or vectors related to Java-Script JIT.

Original advisories

MFSA

Related products

Mozilla-Firefox

Mozilla-SeaMonkey

Mozilla-Firefox-ESR

CVE list

CVE-2015-0818 critical

CVE-2015-0817 high

Solution

Update to latest versionDownload Mozilla Firefox

Download Mozilla Firefox ESR

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

Affected Products

  • Firefox versions earlier than 36.0.4Firefox ESR versions earlier than 31.5.3SeaMonkey versions earlier than 2.33.1

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.201

Percentile

96.4%