Lucene search

K
nvd[email protected]NVD:CVE-2015-0813
HistoryApr 01, 2015 - 10:59 a.m.

CVE-2015-0813

2015-04-0110:59:12
web.nvd.nist.gov

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.045

Percentile

92.5%

Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file.

Affected configurations

NVD
Node
mozillafirefoxRange36.0.4
OR
mozillafirefox_esrRange31.5.3
OR
mozillathunderbirdRange31.5
AND
linuxlinux_kernel

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.045

Percentile

92.5%