CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
Percentile
83.6%
Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in
Mozilla Firefox before 36.0, might allow remote attackers to trigger
problematic Developer Console information or possibly have unspecified
other impact by leveraging incorrect macro expansion, related to the
ots::ots_gasp_parse function.
www.mozilla.org/security/announce/2015/mfsa2015-23.html
bugzilla.mozilla.org/show_bug.cgi?id=1098497
github.com/khaledhosny/ots/commit/003c62d28ae438aa8943cb31535563397f838a2c
launchpad.net/bugs/cve/CVE-2015-0823
nvd.nist.gov/vuln/detail/CVE-2015-0823
security-tracker.debian.org/tracker/CVE-2015-0823
ubuntu.com/security/notices/USN-2505-1
www.cve.org/CVERecord?id=CVE-2015-0823
www.mozilla.org/en-US/security/advisories/mfsa2015-23/