6.4
CVSSv2

CVE-2015-0811

Published: 01/04/2015 Updated: 30/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

The QCMS implementation in Mozilla Firefox prior to 37.0 allows remote malicious users to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly handled during transformation.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

opensuse opensuse 13.2

opensuse opensuse 13.1

canonical ubuntu linux 14.10

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2015-34 Out of bounds read in QCMS library Announced March 31, 2015 Reporter Felix Gröbert Impact Moderate Products Firefox, Firefox OS, SeaMonkey Fixed in ...
The QCMS implementation in Mozilla Firefox before 370 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly handled during transformation ...