PT-2015-2621 · Mozilla+1 · Firefox+1
Frédéric Wang
+1
·
Published
2015-11-05
·
Updated
2024-12-12
·
CVE-2015-7192
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mozilla Firefox versions prior to 42.0
Description
The issue is related to improper interaction between the accessibility-tools feature and the implementation of the TABLE element, allowing remote attackers to cause a denial of service or possibly execute arbitrary code by using an
NSAccessibilityIndexAttribute value to reference a row index. This can be achieved by exploiting errors in the code, potentially enabling a remote attacker to crash the application or execute arbitrary code.Recommendations
For versions prior to 42.0, update to version 42.0 or later to resolve the issue.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox
Suse