CVE-2015-4507
published 2015-09-24CVE-2015-4507: The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a…
PriorityP429medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
3.21%
86.9th percentile
The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbitrary code via a crafted web site.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 40.0.3 | — |
| mozilla | firefox | >= 0 < 41.0+build3-0ubuntu0.14.04.1 | 41.0+build3-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 41.0.1+build2-0ubuntu0.14.04.1 | 41.0.1+build2-0ubuntu0.14.04.1 |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v49m-w8x3-qx4g: The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41
ghsa_unreviewed·2022-05-17
CVE-2015-4507 [MEDIUM] GHSA-v49m-w8x3-qx4g: The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41
The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbitrary code via a crafted web site.
OSV
firefox regression
osv·2015-10-05·CVSS 7.5
[HIGH] firefox regression
firefox regression
USN-2743-1 fixed vulnerabilities in Firefox. After upgrading, some users
reported problems with bookmark creation and crashes in some
circumstances. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Andrew Osmond, Olli Pettay, Andrew Sutherland, Christian Holler, David
Major, Andrew McCreight, Cameron McCormack, Bob Clary and Randell Jesup
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-4500, CVE-2015-4501)
André Bargull discovered that when a web page creates a scripted pro
OSV
unity-firefox-extension, webapps-greasemonkey, webaccounts-browser-extension update
osv·2015-09-24·CVSS 7.5
[HIGH] unity-firefox-extension, webapps-greasemonkey, webaccounts-browser-extension update
unity-firefox-extension, webapps-greasemonkey, webaccounts-browser-extension update
USN-2743-1 fixed vulnerabilities in Firefox. Future Firefox updates will
require all addons be signed and unity-firefox-extension, webapps-greasemonkey
and webaccounts-browser-extension will not go through the signing process.
Because these addons currently break search engine installations (LP:
#1069793), this update permanently disables the addons by removing them from
the system.
We apologize for any inconvenience.
Original advisory details:
Andrew Osmond, Olli Pettay, Andrew Sutherland, Christian Holler, David
Major, Andrew McCreight, Cameron McCormack, Bob Clary and Randell Jesup
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, a
OSV
ubufox update
osv·2015-09-22·CVSS 7.5
[HIGH] ubufox update
ubufox update
USN-2743-1 fixed vulnerabilities in Firefox. This update provides the
corresponding update for Ubufox.
Original advisory details:
Andrew Osmond, Olli Pettay, Andrew Sutherland, Christian Holler, David
Major, Andrew McCreight, Cameron McCormack, Bob Clary and Randell Jesup
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-4500, CVE-2015-4501)
André Bargull discovered that when a web page creates a scripted proxy
for the window with a handler defined a certain way, a reference to the
inner window will be passed, rather than tha
OSV
firefox vulnerabilities
osv·2015-09-22·CVSS 7.5
CVE-2015-4500 [HIGH] firefox vulnerabilities
firefox vulnerabilities
Andrew Osmond, Olli Pettay, Andrew Sutherland, Christian Holler, David
Major, Andrew McCreight, Cameron McCormack, Bob Clary and Randell Jesup
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-4500, CVE-2015-4501)
André Bargull discovered that when a web page creates a scripted proxy
for the window with a handler defined a certain way, a reference to the
inner window will be passed, rather than that of the outer window.
(CVE-2015-4502)
Felix Gröbert discovered an out-of-bounds read in the QCMS color
management librar
OSV
CVE-2015-4507: The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41
osv·2015-09-22·CVSS 5.1
CVE-2015-4507 [MEDIUM] CVE-2015-4507: The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41
The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbitrary code via a crafted web site.
Ubuntu
Firefox regression
vendor_ubuntu·2015-10-05·CVSS 7.5
[HIGH] Firefox regression
Title: Firefox regression
Summary: USN-2743-1 introduced a regression in Firefox.
USN-2743-1 fixed vulnerabilities in Firefox. After upgrading, some users
reported problems with bookmark creation and crashes in some
circumstances. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Andrew Osmond, Olli Pettay, Andrew Sutherland, Christian Holler, David
Major, Andrew McCreight, Cameron McCormack, Bob Clary and Randell Jesup
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-4500, CVE-2015-4501)
Andr
Ubuntu
Unity Integration for Firefox, Unity Websites Integration and Ubuntu Online Accounts extension update
vendor_ubuntu·2015-09-24·CVSS 7.5
[HIGH] Unity Integration for Firefox, Unity Websites Integration and Ubuntu Online Accounts extension update
Title: Unity Integration for Firefox, Unity Websites Integration and Ubuntu Online Accounts extension update
Summary: This update provides compatible packages for Firefox 41
USN-2743-1 fixed vulnerabilities in Firefox. Future Firefox updates will
require all addons be signed and unity-firefox-extension, webapps-greasemonkey
and webaccounts-browser-extension will not go through the signing process.
Because these addons currently break search engine installations (LP:
#1069793), this update permanently disables the addons by removing them from
the system.
We apologize for any inconvenience.
Original advisory details:
Andrew Osmond, Olli Pettay, Andrew Sutherland, Christian Holler, David
Major, Andrew McCreight, Cameron McCormack, Bob Clary and Randell Jesup
discovered multiple memory sa
Ubuntu
Ubufox update
vendor_ubuntu·2015-09-22·CVSS 7.5
[HIGH] Ubufox update
Title: Ubufox update
Summary: This update provides compatible packages for Firefox 41
USN-2743-1 fixed vulnerabilities in Firefox. This update provides the
corresponding update for Ubufox.
Original advisory details:
Andrew Osmond, Olli Pettay, Andrew Sutherland, Christian Holler, David
Major, Andrew McCreight, Cameron McCormack, Bob Clary and Randell Jesup
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-4500, CVE-2015-4501)
André Bargull discovered that when a web page creates a scripted proxy
for the window with a handler defined a cer
Red Hat
Mozilla: Crash when using debugger with SavedStacks in JavaScript (MFSA 2015-102)
vendor_redhat·2015-09-22·CVSS 5.1
CVE-2015-4507 [MEDIUM] CWE-120 Mozilla: Crash when using debugger with SavedStacks in JavaScript (MFSA 2015-102)
Mozilla: Crash when using debugger with SavedStacks in JavaScript (MFSA 2015-102)
The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbitrary code via a crafted web site.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 7) - Not affected
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-09-22·CVSS 7.5
CVE-2015-4500 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Andrew Osmond, Olli Pettay, Andrew Sutherland, Christian Holler, David
Major, Andrew McCreight, Cameron McCormack, Bob Clary and Randell Jesup
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-4500, CVE-2015-4501)
André Bargull discovered that when a web page creates a scripted proxy
for the window with a handler defined a certain way, a reference to the
inner window will be passed, rather than that of the o
No detection rules found.
No public exploits indexed.
arXiv
CryptoQA: A Large-scale Question-answering Dataset for AI-assisted Cryptography
arxiv_fulltext·2025-12-02
CryptoQA: A Large-scale Question-answering Dataset for AI-assisted Cryptography
[CryptoQA]CryptoQA: A Large-scale Question-answering Dataset for AI-assisted
Cryptography
Mayar Elfares, Pascal Reisert, Tilman Dietz, Manpa Barman, Ahmed Zaki, Ralf Küsters, Andreas Bulling
University of Stuttgart
Germany
Elfares et al.
## Abstract
Large language models (LLMs) excel at many general-purpose natural language processing tasks.
However, their ability to perform deep reasoning and mathematical analysis, particularly for complex tasks as required in cryptography, remains poorly understood, largely due to the lack of suitable data for evaluation and training.
To address this gap, we present , the first large-scale question-answering (QA) dataset specifically designed for cryptography.
contains over two million QA pairs drawn from curated academic sources, along with context
Bugzilla
CVE-2015-4507 Mozilla: Crash when using debugger with SavedStacks in JavaScript (MFSA 2015-102)
bugzilla·2015-09-23·CVSS 5.1
CVE-2015-4507 [MEDIUM] CVE-2015-4507 Mozilla: Crash when using debugger with SavedStacks in JavaScript (MFSA 2015-102)
CVE-2015-4507 Mozilla: Crash when using debugger with SavedStacks in JavaScript (MFSA 2015-102)
Security researcher Spandan Veggalam reported a crash while using the debugger
API with SavedStacks in JavaScript. This crash can only occurs when the
debugger is in use but may be potentially exploitable.
Upstream bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=1192401
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2015-102/
Discussion:
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Spandan Veggalam as the original reporter.
---
This issue was fixed in Firefox version 41.
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00005.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-102.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/76815http://www.securitytracker.com/id/1033640http://www.ubuntu.com/usn/USN-2743-1http://www.ubuntu.com/usn/USN-2743-2http://www.ubuntu.com/usn/USN-2743-3http://www.ubuntu.com/usn/USN-2743-4https://bugzilla.mozilla.org/show_bug.cgi?id=1192401http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00005.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-102.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/76815http://www.securitytracker.com/id/1033640http://www.ubuntu.com/usn/USN-2743-1http://www.ubuntu.com/usn/USN-2743-2http://www.ubuntu.com/usn/USN-2743-3http://www.ubuntu.com/usn/USN-2743-4https://bugzilla.mozilla.org/show_bug.cgi?id=1192401
2015-09-24
Published