Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-2729
HistoryJul 05, 2015 - 12:00 a.m.

CVE-2015-2729

2015-07-0500:00:00
ubuntu.com
ubuntu.com
16

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.004

Percentile

74.8%

The AudioParamTimeline::AudioNodeInputValue function in the Web Audio
implementation in Mozilla Firefox before 39.0 and Firefox ESR 38.x before
38.1 does not properly calculate an oscillator rendering range, which
allows remote attackers to obtain sensitive information from process memory
or cause a denial of service (out-of-bounds read) via unspecified vectors.

OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchfirefox< 39.0+build5-0ubuntu0.12.04.2UNKNOWN
ubuntu14.04noarchfirefox< 39.0+build5-0ubuntu0.14.04.1UNKNOWN
ubuntu14.10noarchfirefox< 39.0+build5-0ubuntu0.14.10.1UNKNOWN
ubuntu15.04noarchfirefox< 39.0+build5-0ubuntu0.15.04.1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.004

Percentile

74.8%