CVE-2015-0831
published 2015-02-25CVE-2015-0831: Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.16%
89.7th percentile
Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation.
Affected
234 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| mozilla | firefox | <= 35.0.1 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox regression
vendor_ubuntu·2015-03-09·CVSS 4.3
[MEDIUM] Firefox regression
Title: Firefox regression
Summary: USN-2505-1 introduced a regression in Firefox.
USN-2505-1 fixed vulnerabilities in Firefox. This update removed the
deprecated "-remote" command-line switch that some older software still
depends on. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Matthew Noorenberghe discovered that allowlisted Mozilla domains could
make UITour API calls from background tabs. If one of these domains were
compromised and open in a background tab, an attacker could potentially
exploit this to conduct clickjacking attacks. (CVE-2015-0819)
Jan de Mooij discovered an issue that affects content using the Caja
Compiler. If web content loads specially crafted code, this could be used
to bypass sandboxing security measures provi
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2015-03-03·CVSS 4.3
CVE-2015-0822 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Armin Razmdjou discovered that contents of locally readable files could
be made available via manipulation of form autocomplete in some
circumstances. If a user were tricked in to opening a specially crafted
message with scripting enabled, an attacker could potentially exploit this
to obtain sensitive information. (CVE-2015-0822)
Abhishek Arya discovered an out-of-bounds read and write when rendering
SVG content in some circumstances. If a user were tricked in to opening
a specially crafted message with scripting enabled, an attacker could
potentially exploit this to obtain sensitive information. (CVE-2015-0827)
Paul Bandha discovered a use-after-free in IndexedDB. If a user were
tricked in t
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-02-25·CVSS 4.3
CVE-2015-0819 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Matthew Noorenberghe discovered that Mozilla domains in the allowlist
could make UITour API calls from background tabs. If one of these domains
were compromised and open in a background tab, an attacker could
potentially exploit this to conduct clickjacking attacks. (CVE-2015-0819)
Jan de Mooij discovered an issue that affects content using the Caja
Compiler. If web content loads specially crafted code, this could be used
to bypass sandboxing security measures provided by Caja. (CVE-2015-0820)
Armin Razmdjou discovered that opening hyperlinks with specific mouse
and key combinations could allow a Chrome privileged URL to be opened
without context restri
Red Hat
Mozilla: Use-after-free in IndexedDB (MFSA 2015-16)
vendor_redhat·2015-02-24·CVSS 6.8
CVE-2015-0831 [MEDIUM] CWE-416 Mozilla: Use-after-free in IndexedDB (MFSA 2015-16)
Mozilla: Use-after-free in IndexedDB (MFSA 2015-16)
Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation.
GHSA
GHSA-7fwr-rxv9-jvxf: Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36
ghsa_unreviewed·2022-05-14
CVE-2015-0831 [MEDIUM] GHSA-7fwr-rxv9-jvxf: Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36
Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation.
OSV
firefox regression
osv·2015-03-09·CVSS 4.3
[MEDIUM] firefox regression
firefox regression
USN-2505-1 fixed vulnerabilities in Firefox. This update removed the
deprecated "-remote" command-line switch that some older software still
depends on. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Matthew Noorenberghe discovered that allowlisted Mozilla domains could
make UITour API calls from background tabs. If one of these domains were
compromised and open in a background tab, an attacker could potentially
exploit this to conduct clickjacking attacks. (CVE-2015-0819)
Jan de Mooij discovered an issue that affects content using the Caja
Compiler. If web content loads specially crafted code, this could be used
to bypass sandboxing security measures provided by Caja. (CVE-2015-0820)
Armin Razmdjou discovered that ope
OSV
thunderbird vulnerabilities
osv·2015-03-03·CVSS 4.3
CVE-2015-0822 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Armin Razmdjou discovered that contents of locally readable files could
be made available via manipulation of form autocomplete in some
circumstances. If a user were tricked in to opening a specially crafted
message with scripting enabled, an attacker could potentially exploit this
to obtain sensitive information. (CVE-2015-0822)
Abhishek Arya discovered an out-of-bounds read and write when rendering
SVG content in some circumstances. If a user were tricked in to opening
a specially crafted message with scripting enabled, an attacker could
potentially exploit this to obtain sensitive information. (CVE-2015-0827)
Paul Bandha discovered a use-after-free in IndexedDB. If a user were
tricked in to opening a specially crafted message with scripting enabled,
an att
OSV
firefox vulnerabilities
osv·2015-02-25·CVSS 4.3
CVE-2015-0819 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Matthew Noorenberghe discovered that Mozilla domains in the allowlist
could make UITour API calls from background tabs. If one of these domains
were compromised and open in a background tab, an attacker could
potentially exploit this to conduct clickjacking attacks. (CVE-2015-0819)
Jan de Mooij discovered an issue that affects content using the Caja
Compiler. If web content loads specially crafted code, this could be used
to bypass sandboxing security measures provided by Caja. (CVE-2015-0820)
Armin Razmdjou discovered that opening hyperlinks with specific mouse
and key combinations could allow a Chrome privileged URL to be opened
without context restrictions being preserved. If a user were tricked in to
opening a specially crafted website, an attacker could pote
OSV
CVE-2015-0831: Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36
osv·2015-02-25·CVSS 6.8
CVE-2015-0831 [MEDIUM] CVE-2015-0831: Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36
Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation.
No detection rules found.
No public exploits indexed.
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities
blogs_talos·2015-03-17·CVSS 9.3
[CRITICAL] Research Spotlight: Exploiting Use-After-Free Vulnerabilities
This blog post was authored by Earl Carter & Yves Younan.
Talos is constantly researching the ways in which threat actors take advantage of security weaknesses to exploit systems. Yves Younan of Talos will be presenting at CanSecWest on Friday March 20th. The topic of his talk will be FreeSentry, a software-based mitigation technique developed by Talos to protect against exploitation of use-after-free vulnerabilities. Use-after-free vulnerabilities have become an important class of security problems due to the existence of mitigations that protect against other types of vulnerabilities, such as buffer overflows.
Just examining the CVE entries for 2015, you can already see over 20 use-after-free vulnerabilities that have already been identified, impacting various common software applicati
Talos
Research Spotlight: Exploiting Use-After-Free Vulnerabilities
blogs_talos·2015-03-17·CVSS 9.3
[CRITICAL] Research Spotlight: Exploiting Use-After-Free Vulnerabilities
## Research Spotlight: Exploiting Use-After-Free Vulnerabilities
This blog post was authored by Earl Carter & Yves Younan .
Talos is constantly researching the ways in which threat actors take advantage of security weaknesses to exploit systems. Yves Younan of Talos will be presenting at CanSecWest on Friday March 20th. The topic of his talk will be FreeSentry , a software-based mitigation technique developed by Talos to protect against exploitation of use-after-free vulnerabilities. Use-after-free vulnerabilities have become an important class of security problems due to the existence of mitigations that protect against other types of vulnerabilities, such as buffer overflows.
Just examining the CVE entries for 2015, you can already see over 20 use-after-free vulnerabilities that have
Bugzilla
CVE-2015-0831 Mozilla: Use-after-free in IndexedDB (MFSA 2015-16)
bugzilla·2015-02-24·CVSS 6.8
CVE-2015-0831 [MEDIUM] CVE-2015-0831 Mozilla: Use-after-free in IndexedDB (MFSA 2015-16)
CVE-2015-0831 Mozilla: Use-after-free in IndexedDB (MFSA 2015-16)
Security researcher Paul Bandha used the used the Address Sanitizer tool to discover a use-after-free vulnerability when running specific web content with IndexedDB to create an index. This leads to a potentially exploitable crash.
In general this flaw cannot be exploited through email in the Thunderbird product because scripting is disabled, but is potentially a risk in browser or browser-like contexts
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2015-16
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Paul Bandha as the original reporter.
Discussion:
This issue has been addressed in the following products:
Red Hat Enter
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00067.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0265.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0266.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0642.htmlhttp://www.debian.org/security/2015/dsa-3174http://www.debian.org/security/2015/dsa-3179http://www.mozilla.org/security/announce/2015/mfsa2015-16.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72746http://www.securitytracker.com/id/1031791http://www.securitytracker.com/id/1031792http://www.ubuntu.com/usn/USN-2505-1http://www.ubuntu.com/usn/USN-2506-1https://bugzilla.mozilla.org/show_bug.cgi?id=1130541https://security.gentoo.org/glsa/201504-01http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00067.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0265.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0266.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0642.htmlhttp://www.debian.org/security/2015/dsa-3174http://www.debian.org/security/2015/dsa-3179http://www.mozilla.org/security/announce/2015/mfsa2015-16.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72746http://www.securitytracker.com/id/1031791http://www.securitytracker.com/id/1031792http://www.ubuntu.com/usn/USN-2505-1http://www.ubuntu.com/usn/USN-2506-1https://bugzilla.mozilla.org/show_bug.cgi?id=1130541https://security.gentoo.org/glsa/201504-01
2015-02-25
Published