CVE-2015-4509

CVSS v2.0 7.5 (High)
75% Progress
EPSS 21.48 % (97th)
21.48% Progress
Affected Products 2
Advisories 10

Use-after-free vulnerability in the HTMLVideoElement interface in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via crafted JavaScript code that modifies the URI table of a media element, aka ZDI-CAN-3176.

Weaknesses
CWE-NVD-Other
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2015-09-24 04:59:12
(9 years ago)
Updated Date
2016-12-22 02:59:55
(7 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox Esr 38.0 cpe:2.3:a:mozilla:firefox_esr:38.0
  Mozilla Firefox Esr 38.0.1 cpe:2.3:a:mozilla:firefox_esr:38.0.1
  Mozilla Firefox Esr 38.0.5 cpe:2.3:a:mozilla:firefox_esr:38.0.5
  Mozilla Firefox Esr 38.1.0 cpe:2.3:a:mozilla:firefox_esr:38.1.0
  Mozilla Firefox Esr 38.1.1 cpe:2.3:a:mozilla:firefox_esr:38.1.1
  Mozilla Firefox Esr 38.2.0 cpe:2.3:a:mozilla:firefox_esr:38.2.0
  Mozilla Firefox Esr 38.2.1 cpe:2.3:a:mozilla:firefox_esr:38.2.1

Configuration #2

    CPE23 From Up To
  Mozilla Firefox 40.0.3 and prior versions cpe:2.3:a:mozilla:firefox <= 40.0.3
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...