cbcvebase.
CVE-2015-2716
published 2015-05-14

CVE-2015-2716: Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute…

PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.42%
93.8th percentile
Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.

Affected

54 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianexpat< expat 2.1.1-2 (bookworm)expat 2.1.1-2 (bookworm)
debianexpat< expat 2.1.0-7 (bookworm)expat 2.1.0-7 (bookworm)
debianlibxmltok< expat 2.1.1-2 (bookworm)expat 2.1.1-2 (bookworm)
debianlibxmltok< expat 2.1.0-7 (bookworm)expat 2.1.0-7 (bookworm)
googlechrome<= 43.0.2357.134
libexpat_projectlibexpat<= 2.1.0
libexpat_projectlibexpat<= 2.1.1
mcafeepolicy_auditor< 6.5.16.5.1
mozillafirefox<= 37.0.2
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox>= 0 < 38.0+build3-0ubuntu0.14.04.138.0+build3-0ubuntu0.14.04.1
mozillafirefox_esr
mozillafirefox_esr

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.