7.5
CVSSv2

CVE-2015-0803

Published: 01/04/2015 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox prior to 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote malicious users to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 14.10

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

opensuse opensuse 13.1

opensuse opensuse 13.2

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2015-39 Use-after-free due to type confusion flaws Announced March 31, 2015 Reporter Nils Impact Critical Products Firefox, SeaMonkey Fixed in ...
The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 370 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document ...