CVE-2015-4504

CVSS v2.0 6.4 (Medium)
64% Progress
EPSS 5.41 % (93th)
5.41% Progress
Affected Products 1
Advisories 2

The lut_inverse_interp16 function in the QCMS library in Mozilla Firefox before 41.0 allows remote attackers to obtain sensitive information or cause a denial of service (buffer over-read and application crash) via crafted attributes in the ICC 4 profile of an image.

Weaknesses
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2015-09-24 04:59:07
(9 years ago)
Updated Date
2016-12-22 02:59:55
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 40.0.3 and prior versions cpe:2.3:a:mozilla:firefox <= 40.0.3
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...