Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-7179
HistorySep 24, 2015 - 12:00 a.m.

CVE-2015-7179

2015-09-2400:00:00
ubuntu.com
ubuntu.com
15

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.087

Percentile

94.5%

The VertexBufferInterface::reserveVertexSpace function in libGLES in ANGLE,
as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on
Windows, incorrectly allocates memory for shader attribute arrays, which
allows remote attackers to execute arbitrary code or cause a denial of
service (buffer overflow and application crash) via crafted (1) OpenGL or
(2) WebGL content.

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.087

Percentile

94.5%