CVE-2015-4509 — Use After Free in Mozilla Firefox
Severity
7.5HIGHNVD
EPSS
4.9%
top 10.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateMay 17
Description
Use-after-free vulnerability in the HTMLVideoElement interface in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via crafted JavaScript code that modifies the URI table of a media element, aka ZDI-CAN-3176.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages3 packages
🔴Vulnerability Details
7GHSA▶
GHSA-55pq-p5vr-w7hc: Use-after-free vulnerability in the HTMLVideoElement interface in Mozilla Firefox before 41↗2022-05-17
📋Vendor Advisories
6Ubuntu▶
Unity Integration for Firefox, Unity Websites Integration and Ubuntu Online Accounts extension update↗2015-09-24
💬Community
1Bugzilla▶
CVE-2015-4509 Mozilla: Use-after-free while manipulating HTML media content (MFSA 2015-106)↗2015-09-22