CVE-2015-2706Race Condition in Mozilla Firefox

Severity
6.8MEDIUMNVD
EPSS
1.1%
top 21.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 27
Latest updateMay 17

Description

Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted plugin that does not properly complete initialization.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages2 packages

Ubuntumozilla/firefox< 37.0.2+build1-0ubuntu0.14.04.1
NVDmozilla/firefox37.0.1

🔴Vulnerability Details

3
GHSA
GHSA-xwcx-vhr3-5qc7: Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 372022-05-17
OSV
firefox vulnerability2015-04-24
OSV
CVE-2015-2706: Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 372015-04-21

📋Vendor Advisories

2
Ubuntu
Firefox vulnerability2015-04-24
Red Hat
Mozilla: Memory corruption during failed plugin initialization (MFSA 2015-45)2015-04-20

💬Community

1
Bugzilla
CVE-2015-2706 Mozilla: Memory corruption during failed plugin initialization (MFSA 2015-45)2015-04-21