CVE-2015-0824 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Mozilla Firefox
Severity
5.0MEDIUMNVD
OSV4.3
EPSS
1.6%
top 18.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 25
Latest updateMay 14
Description
The mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 36.0 allows remote attackers to cause a denial of service (out-of-bounds write of zero values, and application crash) via vectors that trigger use of DrawTarget and the Cairo library for image drawing.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9
Affected Packages3 packages
Also affects: Ubuntu Linux 12.04, 14.04, 14.10
🔴Vulnerability Details
4📋Vendor Advisories
3💬Community
1Bugzilla
▶