cbcvebase.
CVE-2015-4506
published 2015-09-24

CVE-2015-4506: Buffer overflow in the vp9_init_context_buffers function in libvpx, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3, allows remote…

PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.92%
91.2th percentile
Buffer overflow in the vp9_init_context_buffers function in libvpx, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3, allows remote attackers to execute arbitrary code via a crafted VP9 file.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlibvpx< libvpx 1.4.0-4 (bookworm)libvpx 1.4.0-4 (bookworm)
mozillafirefox<= 40.0.3
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox>= 0 < 41.0+build3-0ubuntu0.14.04.141.0+build3-0ubuntu0.14.04.1
mozillafirefox>= 0 < 41.0.1+build2-0ubuntu0.14.04.141.0.1+build2-0ubuntu0.14.04.1
mozillathunderbird>= 0 < 1:38.3.0+build1-0ubuntu0.14.04.11:38.3.0+build1-0ubuntu0.14.04.1
webmprojectlibvpx>= 0 < 1.4.0-41.4.0-4
webmprojectlibvpx>= 0 < 1.4.0-41.4.0-4
webmprojectlibvpx>= 0 < 1.4.0-41.4.0-4
webmprojectlibvpx>= 0 < 1.4.0-41.4.0-4

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.