CVE-2015-4511
published 2015-09-24CVE-2015-4511: Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to…
PriorityP338medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.77%
90.9th percentile
Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via a crafted header in a WebM video.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 40.0.3 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 41.0+build3-0ubuntu0.14.04.1 | 41.0+build3-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:38.3.0+build1-0ubuntu0.14.04.1 | 1:38.3.0+build1-0ubuntu0.14.04.1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mhrf-5mvv-xxp7: Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41
ghsa_unreviewed·2022-05-17
CVE-2015-4511 [MEDIUM] CWE-119 GHSA-mhrf-5mvv-xxp7: Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41
Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via a crafted header in a WebM video.
OSV
thunderbird vulnerabilities
osv·2015-10-05·CVSS 7.5
CVE-2015-4500 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Andrew Osmond, Olli Pettay, Andrew Sutherland, Christian Holler, David
Major, Andrew McCreight, and Cameron McCormack discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary code
with the privileges of the user invoking Thunderbird. (CVE-2015-4500)
Khalil Zhani discovered a buffer overflow when parsing VP9 content in some
circumstances. If a user were tricked in to opening a specially crafted
message, an attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary code with the
privileges of the user invoking Thunderbird. (CVE-2
OSV
CVE-2015-4511: Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41
osv·2015-09-23·CVSS 6.8
CVE-2015-4511 [MEDIUM] CVE-2015-4511: Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41
Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via a crafted header in a WebM video.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2015-10-05·CVSS 7.5
CVE-2015-4500 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Andrew Osmond, Olli Pettay, Andrew Sutherland, Christian Holler, David
Major, Andrew McCreight, and Cameron McCormack discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary code
with the privileges of the user invoking Thunderbird. (CVE-2015-4500)
Khalil Zhani discovered a buffer overflow when parsing VP9 content in some
circumstances. If a user were tricked in to opening a specially crafted
message, an attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitra
Red Hat
Mozilla: Buffer overflow while decoding WebM video (MFSA 2015-105)
vendor_redhat·2015-09-22·CVSS 6.8
CVE-2015-4511 [MEDIUM] CWE-120 Mozilla: Buffer overflow while decoding WebM video (MFSA 2015-105)
Mozilla: Buffer overflow while decoding WebM video (MFSA 2015-105)
Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via a crafted header in a WebM video.
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1834.htmlhttp://www.debian.org/security/2015/dsa-3365http://www.mozilla.org/security/announce/2015/mfsa2015-105.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/76816http://www.securitytracker.com/id/1033640http://www.ubuntu.com/usn/USN-2754-1https://bugzilla.mozilla.org/show_bug.cgi?id=1200148http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1834.htmlhttp://www.debian.org/security/2015/dsa-3365http://www.mozilla.org/security/announce/2015/mfsa2015-105.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/76816http://www.securitytracker.com/id/1033640http://www.ubuntu.com/usn/USN-2754-1https://bugzilla.mozilla.org/show_bug.cgi?id=1200148
2015-09-24
Published