Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-0823
HistoryFeb 25, 2015 - 12:00 a.m.

CVE-2015-0823

2015-02-2500:00:00
ubuntu.com
ubuntu.com
15

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.01

Percentile

83.6%

Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in
Mozilla Firefox before 36.0, might allow remote attackers to trigger
problematic Developer Console information or possibly have unspecified
other impact by leveraging incorrect macro expansion, related to the
ots::ots_gasp_parse function.

OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchfirefox< 36.0+build2-0ubuntu0.12.04.5UNKNOWN
ubuntu14.04noarchfirefox< 36.0+build2-0ubuntu0.14.04.4UNKNOWN
ubuntu14.10noarchfirefox< 36.0+build2-0ubuntu0.14.10.4UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.01

Percentile

83.6%