7.5
CVSSv2

CVE-2015-0806

Published: 01/04/2015 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox prior to 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote malicious users to execute arbitrary code or cause a denial of service (memory corruption) via vectors that trigger rendering of 2D graphics content.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 14.10

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

mozilla firefox

opensuse opensuse 13.2

opensuse opensuse 13.1

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2015-38 Memory corruption crashes in Off Main Thread Compositing Announced March 31, 2015 Reporter Abhishek Arya Impact Critical Products Firefox, Firefox OS, SeaMonkey Fixed in ...
The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 370 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via ...