CVE-2015-4497
published 2015-08-29CVE-2015-4497: Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote…
PriorityP347critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
8.01%
94.1th percentile
Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 40.0.3+build1-0ubuntu0.14.04.1 | 40.0.3+build1-0ubuntu0.14.04.1 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Use-after-free when resizing canvas element during restyling (MFSA 2015-94)
vendor_redhat·2015-08-27·CVSS 10.0
CVE-2015-4497 [CRITICAL] CWE-416 Mozilla: Use-after-free when resizing canvas element during restyling (MFSA 2015-94)
Mozilla: Use-after-free when resizing canvas element during restyling (MFSA 2015-94)
Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-08-27·CVSS 10.0
CVE-2015-4497 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
A use-after-free was discovered when resizing a canvas element during
restyling in some circumstances. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service via application crash, or execute arbitrary code
with the privileges of the user invoking Firefox. (CVE-2015-4497)
Bas Venis discovered that the addon install permission prompt could be
bypassed using data: URLs in some circumstances. It was also discovered
that the installation notification could be made to appear over another
site. If a user were tricked in to opening a specially crafted website, an
attacker could p
GHSA
GHSA-v9wp-mjxj-3vqc: Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40
ghsa_unreviewed·2022-05-17
CVE-2015-4497 [HIGH] GHSA-v9wp-mjxj-3vqc: Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40
Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.
OSV
firefox vulnerabilities
osv·2015-08-27·CVSS 10.0
CVE-2015-4497 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
A use-after-free was discovered when resizing a canvas element during
restyling in some circumstances. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service via application crash, or execute arbitrary code
with the privileges of the user invoking Firefox. (CVE-2015-4497)
Bas Venis discovered that the addon install permission prompt could be
bypassed using data: URLs in some circumstances. It was also discovered
that the installation notification could be made to appear over another
site. If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to install a malicious addon.
(CVE-2015-4498)
OSV
CVE-2015-4497: Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40
osv·2015-08-27·CVSS 10.0
CVE-2015-4497 [CRITICAL] CVE-2015-4497: Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40
Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1693.htmlhttp://www.debian.org/security/2015/dsa-3345http://www.mozilla.org/security/announce/2015/mfsa2015-94.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/76502http://www.securitytracker.com/id/1033397http://www.ubuntu.com/usn/USN-2723-1http://www.zerodayinitiative.com/advisories/ZDI-15-406https://bugzilla.mozilla.org/show_bug.cgi?id=1164766https://bugzilla.mozilla.org/show_bug.cgi?id=1175278http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1693.htmlhttp://www.debian.org/security/2015/dsa-3345http://www.mozilla.org/security/announce/2015/mfsa2015-94.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/76502http://www.securitytracker.com/id/1033397http://www.ubuntu.com/usn/USN-2723-1http://www.zerodayinitiative.com/advisories/ZDI-15-406https://bugzilla.mozilla.org/show_bug.cgi?id=1164766https://bugzilla.mozilla.org/show_bug.cgi?id=1175278
2015-08-29
Published