CVE-2015-4507Classic Buffer Overflow in Mozilla Firefox

Severity
5.1MEDIUMNVD
OSV7.5
EPSS
1.2%
top 21.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateDec 2

Description

The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbitrary code via a crafted web site.

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 4.9 | Impact: 6.4

Affected Packages2 packages

Ubuntumozilla/firefox< 41.0+build3-0ubuntu0.14.04.1+1
NVDmozilla/firefox40.0.3

🔴Vulnerability Details

6
GHSA
GHSA-v49m-w8x3-qx4g: The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 412022-05-17
OSV
firefox regression2015-10-05
OSV
unity-firefox-extension, webapps-greasemonkey, webaccounts-browser-extension update2015-09-24
OSV
ubufox update2015-09-22
OSV
firefox vulnerabilities2015-09-22

📋Vendor Advisories

5
Ubuntu
Firefox regression2015-10-05
Ubuntu
Unity Integration for Firefox, Unity Websites Integration and Ubuntu Online Accounts extension update2015-09-24
Ubuntu
Ubufox update2015-09-22
Red Hat
Mozilla: Crash when using debugger with SavedStacks in JavaScript (MFSA 2015-102)2015-09-22
Ubuntu
Firefox vulnerabilities2015-09-22

📄Research Papers

1
arXiv
CryptoQA: A Large-scale Question-answering Dataset for AI-assisted Cryptography2025-12-02

💬Community

1
Bugzilla
CVE-2015-4507 Mozilla: Crash when using debugger with SavedStacks in JavaScript (MFSA 2015-102)2015-09-23