CVE-2015-4487
published 2015-08-16CVE-2015-4487: The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to…
PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.82%
88.9th percentile
The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| mozilla | firefox | <= 39.0.3 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 40.0+build4-0ubuntu0.14.04.1 | 40.0+build4-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 40.0+build4-0ubuntu0.14.04.4 | 40.0+build4-0ubuntu0.14.04.4 |
| mozilla | firefox_os | <= 2.1.0 | — |
| mozilla | thunderbird | >= 0 < 1:38.2.0+build1-0ubuntu0.14.04.1 | 1:38.2.0+build1-0ubuntu0.14.04.1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv10.0CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2015-08-25·CVSS 10.0
CVE-2015-4473 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Gary Kwong, Christian Holler, and Byron Campen discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary code
with the privileges ofthe user invoking Thunderbird. (CVE-2015-4473)
Ronald Crane reported 3 security issues. If a user were tricked in to
opening a specially crafted message, an attacker could potentially
exploit these, in combination with another security vulnerability, to
cause a denial of service via application crash, or execute arbitrary
code with the privileges of the user invoking Thunderbird. (CVE-
Ubuntu
Firefox regression
vendor_ubuntu·2015-08-20·CVSS 10.0
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: USN-2702-1 introduced a regression in Firefox.
USN-2702-1 fixed vulnerabilities in Firefox. After upgrading, some users
in the US reported that their default search engine switched to Yahoo.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Gary Kwong, Christian Holler, Byron Campen, Tyson Smith, Bobby Holley,
Chris Coulson, and Eric Rahm discovered multiple memory safety issues in
Firefox. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to cause a denial of service
via application crash, or execute arbitrary code with the privileges of
the user invoking Firefox. (CVE-2015-4473, CVE-2015-4474)
Aki Helin discovered an out-of-bounds read when play
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-08-11·CVSS 10.0
CVE-2015-4473 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Gary Kwong, Christian Holler, Byron Campen, Tyson Smith, Bobby Holley,
Chris Coulson, and Eric Rahm discovered multiple memory safety issues in
Firefox. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to cause a denial of service
via application crash, or execute arbitrary code with the privileges of
the user invoking Firefox. (CVE-2015-4473, CVE-2015-4474)
Aki Helin discovered an out-of-bounds read when playing malformed MP3
content in some circumstances. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
obtain sensitive informatio
Ubuntu
Ubufox update
vendor_ubuntu·2015-08-11·CVSS 10.0
[CRITICAL] Ubufox update
Title: Ubufox update
Summary: This update provides compatible packages for Firefox 40.
USN-2702-1 fixed vulnerabilities in Firefox. This update provides the
corresponding updates for Ubufox.
Original advisory details:
Gary Kwong, Christian Holler, Byron Campen, Tyson Smith, Bobby Holley,
Chris Coulson, and Eric Rahm discovered multiple memory safety issues in
Firefox. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to cause a denial of service
via application crash, or execute arbitrary code with the privileges of
the user invoking Firefox. (CVE-2015-4473, CVE-2015-4474)
Aki Helin discovered an out-of-bounds read when playing malformed MP3
content in some circumstances. If a user were tricked in to opening a
specially craft
Red Hat
Mozilla: Vulnerabilities found through code inspection (MFSA 2015-90)
vendor_redhat·2015-08-11·CVSS 7.5
CVE-2015-4487 [HIGH] Mozilla: Vulnerabilities found through code inspection (MFSA 2015-90)
Mozilla: Vulnerabilities found through code inspection (MFSA 2015-90)
The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
GHSA
GHSA-99c3-fh27-qg5q: The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40
ghsa_unreviewed·2022-05-14
CVE-2015-4487 [HIGH] CWE-119 GHSA-99c3-fh27-qg5q: The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40
The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
OSV
thunderbird vulnerabilities
osv·2015-08-25·CVSS 10.0
CVE-2015-4473 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Gary Kwong, Christian Holler, and Byron Campen discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary code
with the privileges ofthe user invoking Thunderbird. (CVE-2015-4473)
Ronald Crane reported 3 security issues. If a user were tricked in to
opening a specially crafted message, an attacker could potentially
exploit these, in combination with another security vulnerability, to
cause a denial of service via application crash, or execute arbitrary
code with the privileges of the user invoking Thunderbird. (CVE-2015-4487,
CVE-2015-4488, CVE-2015-4489)
Gustavo Grieco discovered
OSV
firefox regression
osv·2015-08-20·CVSS 10.0
[CRITICAL] firefox regression
firefox regression
USN-2702-1 fixed vulnerabilities in Firefox. After upgrading, some users
in the US reported that their default search engine switched to Yahoo.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Gary Kwong, Christian Holler, Byron Campen, Tyson Smith, Bobby Holley,
Chris Coulson, and Eric Rahm discovered multiple memory safety issues in
Firefox. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to cause a denial of service
via application crash, or execute arbitrary code with the privileges of
the user invoking Firefox. (CVE-2015-4473, CVE-2015-4474)
Aki Helin discovered an out-of-bounds read when playing malformed MP3
content in some circumstances. If a user were
OSV
firefox vulnerabilities
osv·2015-08-11·CVSS 10.0
CVE-2015-4473 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Gary Kwong, Christian Holler, Byron Campen, Tyson Smith, Bobby Holley,
Chris Coulson, and Eric Rahm discovered multiple memory safety issues in
Firefox. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to cause a denial of service
via application crash, or execute arbitrary code with the privileges of
the user invoking Firefox. (CVE-2015-4473, CVE-2015-4474)
Aki Helin discovered an out-of-bounds read when playing malformed MP3
content in some circumstances. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
obtain sensitive information, cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user in
OSV
CVE-2015-4487: The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40
osv·2015-08-11·CVSS 7.5
CVE-2015-4487 [HIGH] CVE-2015-4487: The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40
The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
OSV
ubufox update
osv·2015-08-11·CVSS 10.0
[CRITICAL] ubufox update
ubufox update
USN-2702-1 fixed vulnerabilities in Firefox. This update provides the
corresponding updates for Ubufox.
Original advisory details:
Gary Kwong, Christian Holler, Byron Campen, Tyson Smith, Bobby Holley,
Chris Coulson, and Eric Rahm discovered multiple memory safety issues in
Firefox. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to cause a denial of service
via application crash, or execute arbitrary code with the privileges of
the user invoking Firefox. (CVE-2015-4473, CVE-2015-4474)
Aki Helin discovered an out-of-bounds read when playing malformed MP3
content in some circumstances. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
obtain sensitive
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2015-08/msg00030.htmlhttp://lists.opensuse.org/opensuse-updates/2015-08/msg00031.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1586.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1682.htmlhttp://www.debian.org/security/2015/dsa-3333http://www.debian.org/security/2015/dsa-3410http://www.mozilla.org/security/announce/2015/mfsa2015-90.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securitytracker.com/id/1033247http://www.securitytracker.com/id/1033372http://www.ubuntu.com/usn/USN-2702-1http://www.ubuntu.com/usn/USN-2702-2http://www.ubuntu.com/usn/USN-2702-3http://www.ubuntu.com/usn/USN-2712-1https://bugzilla.mozilla.org/show_bug.cgi?id=1171603https://security.gentoo.org/glsa/201605-06http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2015-08/msg00030.htmlhttp://lists.opensuse.org/opensuse-updates/2015-08/msg00031.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1586.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1682.htmlhttp://www.debian.org/security/2015/dsa-3333http://www.debian.org/security/2015/dsa-3410http://www.mozilla.org/security/announce/2015/mfsa2015-90.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securitytracker.com/id/1033247http://www.securitytracker.com/id/1033372http://www.ubuntu.com/usn/USN-2702-1http://www.ubuntu.com/usn/USN-2702-2http://www.ubuntu.com/usn/USN-2702-3http://www.ubuntu.com/usn/USN-2712-1https://bugzilla.mozilla.org/show_bug.cgi?id=1171603https://security.gentoo.org/glsa/201605-06
2015-08-16
Published