CVE-2015-2706

CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 7.84 % (94th)
7.84% Progress
Affected Products 1
Advisories 3

Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted plugin that does not properly complete initialization.

Weaknesses
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2015-04-27 11:59:07
(9 years ago)
Updated Date
2016-12-07 18:10:21
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 37.0.1 and prior versions cpe:2.3:a:mozilla:firefox <= 37.0.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...