cbcvebase.
CVE-2015-2716
published 2015-05-14

CVE-2015-2716: Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute…

high7.5CVSS 3.1
AVNACLAuNCPIPAP
Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.

Affected

54 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianexpat< expat 2.1.1-2 (bookworm)expat 2.1.1-2 (bookworm)
debianexpat< expat 2.1.0-7 (bookworm)expat 2.1.0-7 (bookworm)
debianlibxmltok< expat 2.1.1-2 (bookworm)expat 2.1.1-2 (bookworm)
debianlibxmltok< expat 2.1.0-7 (bookworm)expat 2.1.0-7 (bookworm)
googlechrome<= 43.0.2357.134
libexpat_projectlibexpat<= 2.1.0
libexpat_projectlibexpat<= 2.1.1
mcafeepolicy_auditor< 6.5.16.5.1
mozillafirefox<= 37.0.2
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox>= 0 < 38.0+build3-0ubuntu0.14.04.138.0+build3-0ubuntu0.14.04.1
mozillafirefox_esr
mozillafirefox_esr

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd7.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH