CVE-2015-0813Use After Free in Mozilla Firefox

CWE-416Use After Free11 documents6 sources
Severity
5.1MEDIUMNVD
OSV7.5
EPSS
2.8%
top 13.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 1
Latest updateMay 17

Description

Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file.

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 4.9 | Impact: 6.4

Affected Packages4 packages

Ubuntumozilla/firefox< 37.0+build2-0ubuntu0.14.04.1
NVDmozilla/firefox31.5.3+1
Ubuntumozilla/thunderbird< 1:31.6.0+build1-0ubuntu0.14.04.1

🔴Vulnerability Details

4
GHSA
GHSA-vjfm-2p57-mvrc: Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 372022-05-17
OSV
thunderbird vulnerabilities2015-04-02
OSV
firefox vulnerabilities2015-04-01
OSV
CVE-2015-0813: Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 372015-04-01

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2015-04-02
Ubuntu
Firefox vulnerabilities2015-04-01
Red Hat
Mozilla: Use-after-free when using the Fluendo MP3 GStreamer plugin (MFSA 2015-31)2015-03-31

💬Community

3
Bugzilla
CVE-2015-0357 CVE-2015-3040 flash-plugin: information leaks leading to ASLR bypass (APSB15-06)2015-04-15
Bugzilla
CVE-2015-3044 flash-plugin: security bypass leading to information disclosure (APSB15-06)2015-04-15
Bugzilla
CVE-2015-0813 Mozilla: Use-after-free when using the Fluendo MP3 GStreamer plugin (MFSA 2015-31)2015-03-30