Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ilxu1A

#40119of 53,632
6.8Total CVSS
Vulnerabilities · 1
PT-2015-1009
6.8
2015-03-20
Mozilla · Firefox Esr · CVE-2015-0817
**Name of the Vulnerable Software and Affected Versions** Mozilla Firefox versions prior to 36.0.3 Mozilla Firefox ESR versions prior to 31.5.2 SeaMonkey versions prior to 2.33.1 **Description** The issue is related to the asm.js implementation, which does not properly determine cases where bounds checking can be safely skipped during JIT compilation and heap access. This allows remote attackers to read or write to unintended memory locations and execute arbitrary code via crafted JavaScript. **Recommendations** For Mozilla Firefox versions prior to 36.0.3, update to version 36.0.3 or later. For Mozilla Firefox ESR versions prior to 31.5.2, update to version 31.5.2 or later. For SeaMonkey versions prior to 2.33.1, update to version 2.33.1 or later.