PT-2015-1759 · Mozilla+3 · Firefox+3
Bwc
+1
·
Published
2015-08-11
·
Updated
2024-06-15
·
CVE-2015-4474
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 40.0
Description
The issue is due to insufficient input validation, allowing remote attackers to potentially execute arbitrary code or cause a denial of service, which may result in memory corruption and application crash. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations
For versions prior to 40.0, update to version 40.0 or later to resolve the issue. As a temporary workaround, consider restricting access to untrusted websites and avoiding suspicious links to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Firefox
Suse
Ubuntu