CVE-2015-2726
published 2015-07-06CVE-2015-2726: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0 allow remote attackers to cause a denial of service (memory…
PriorityP339critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.06%
92.6th percentile
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 38.1.0 | — |
| mozilla | firefox | >= 0 < 39.0+build5-0ubuntu0.14.04.1 | 39.0+build5-0ubuntu0.14.04.1 |
| novell | suse_linux_enterprise_desktop | — | — |
| novell | suse_linux_enterprise_server | — | — |
| novell | suse_linux_enterprise_server | — | — |
| novell | suse_linux_enterprise_software_development_kit | — | — |
| oracle | solaris | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-07-15·CVSS 4.3
CVE-2015-2721 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
USN-2656-1 fixed vulnerabilities in Firefox for Ubuntu 14.04 LTS and
later releases.
This update provides the corresponding update for Ubuntu 12.04 LTS.
Original advisory details:
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Looben Yan discovered 2 use-after-free issues when using XMLHttpRequest in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker c
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-07-09·CVSS 4.3
CVE-2015-2721 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Looben Yan discovered 2 use-after-free issues when using XMLHttpRequest in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2015-2722,
CVE-2015
Red Hat
Mozilla: Miscellaneous memory safety hazards (rv:38.1) (MFSA 2015-59)
vendor_redhat·2015-07-02·CVSS 10.0
CVE-2015-2726 [CRITICAL] Mozilla: Miscellaneous memory safety hazards (rv:38.1) (MFSA 2015-59)
Mozilla: Miscellaneous memory safety hazards (rv:38.1) (MFSA 2015-59)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: thunderbird (Red Hat Enterpris
GHSA
GHSA-hj7w-qcxj-wjmx: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39
ghsa_unreviewed·2022-05-17
CVE-2015-2726 [HIGH] CWE-119 GHSA-hj7w-qcxj-wjmx: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
OSV
vnc4 vulnerabilities
osv·2021-03-15·CVSS 6.4
CVE-2015-0255 vnc4 vulnerabilities
vnc4 vulnerabilities
USN-2500-1 addressed CVE-2015-0255 for xorg-server. This update provides
the corresponding fix for VNC4 on Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
(CVE-2015-0255)
USN-2726-1 addressed CVE-2015-1283 for Expat. This update provides the
corresponding fix for VNC4 on Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
(CVE-2015-1283)
Original advisory details:
Olivier Fourdan discovered that the X.Org X server incorrectly handled
XkbSetGeometry requests resulting in an information leak. An attacker able
to connect to an X server, either locally or remotely, could use this issue
to possibly obtain sensitive information. (CVE-2015-0255)
It was discovered that Expat incorrectly handled malformed XML data. If a
user or application linked against Expat were tricked into opening a
crafte
OSV
firefox vulnerabilities
osv·2015-07-09·CVSS 4.3
CVE-2015-2721 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Looben Yan discovered 2 use-after-free issues when using XMLHttpRequest in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2015-2722,
CVE-2015-2733)
Bob Clary, Christian Holler, Bobby Holley, Andrew McCreight, Terrence
Cole, Steve Fink, Mats Palmgren, W
OSV
CVE-2015-2726: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39
osv·2015-07-05·CVSS 10.0
CVE-2015-2726 [CRITICAL] CVE-2015-2726: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-59.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/75541http://www.securitytracker.com/id/1032783http://www.securitytracker.com/id/1032784http://www.ubuntu.com/usn/USN-2656-1http://www.ubuntu.com/usn/USN-2656-2https://bugzilla.mozilla.org/show_bug.cgi?id=1059081https://bugzilla.mozilla.org/show_bug.cgi?id=1132265https://bugzilla.mozilla.org/show_bug.cgi?id=1145781https://bugzilla.mozilla.org/show_bug.cgi?id=1146416https://bugzilla.mozilla.org/show_bug.cgi?id=1155985https://security.gentoo.org/glsa/201512-10http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-59.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.securityfocus.com/bid/75541http://www.securitytracker.com/id/1032783http://www.securitytracker.com/id/1032784http://www.ubuntu.com/usn/USN-2656-1http://www.ubuntu.com/usn/USN-2656-2https://bugzilla.mozilla.org/show_bug.cgi?id=1059081https://bugzilla.mozilla.org/show_bug.cgi?id=1132265https://bugzilla.mozilla.org/show_bug.cgi?id=1145781https://bugzilla.mozilla.org/show_bug.cgi?id=1146416https://bugzilla.mozilla.org/show_bug.cgi?id=1155985https://security.gentoo.org/glsa/201512-10
2015-07-06
Published