CVE-2015-7203Improper Restriction of Operations within the Bounds of a Memory Buffer in Mozilla Firefox

Severity
10.0CRITICALNVD
EPSS
1.7%
top 17.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 16
Latest updateMay 14

Description

Buffer overflow in the DirectWriteFontInfo::LoadFontFamilyData function in gfx/thebes/gfxDWriteFontList.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted font-family name.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages4 packages

Ubuntumozilla/firefox< 43.0+build1-0ubuntu0.14.04.1
NVDmozilla/firefox42.0
NVDopensuse/leap42.1
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Fedora 22, 23

🔴Vulnerability Details

3
GHSA
GHSA-732x-x6wf-h957: Buffer overflow in the DirectWriteFontInfo::LoadFontFamilyData function in gfx/thebes/gfxDWriteFontList2022-05-14
OSV
CVE-2015-7203: Buffer overflow in the DirectWriteFontInfo::LoadFontFamilyData function in gfx/thebes/gfxDWriteFontList2015-12-15
OSV
firefox vulnerabilities2015-12-15

📋Vendor Advisories

2
Red Hat
Mozilla: Buffer overflows found through code inspection (MFSA 2015-144)2015-12-16
Ubuntu
Firefox vulnerabilities2015-12-15

💬Community

1
Bugzilla
CVE-2015-7203 CVE-2015-7220 CVE-2015-7221 Mozilla: Buffer overflows found through code inspection (MFSA 2015-144)2015-12-15
CVE-2015-7203 — Mozilla Firefox vulnerability | cvebase