cbcvebase.
CVE-2015-4484
published 2015-08-16

CVE-2015-4484: The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows…

PriorityP419medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.27%
89.9th percentile
The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of service (application crash) by leveraging the use of shared memory and accessing (1) an Atomics object or (2) a SharedArrayBuffer object.

Affected

13 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
mozillafirefox<= 39.0.3
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox>= 0 < 40.0+build4-0ubuntu0.14.04.140.0+build4-0ubuntu0.14.04.1
mozillafirefox>= 0 < 40.0+build4-0ubuntu0.14.04.440.0+build4-0ubuntu0.14.04.4
opensuseopensuse
opensuseopensuse
oraclesolaris

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv10.0CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.