7.5
CVSSv2

CVE-2015-0836

Published: 25/02/2015 Updated: 24/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox prior to 36.0, Firefox ESR 31.x prior to 31.5, and Thunderbird prior to 31.5 allow remote malicious users to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox esr 31.1.1

mozilla firefox esr 31.2

mozilla firefox esr 31.5

mozilla firefox esr 31.0

mozilla firefox esr 31.1

mozilla firefox esr 31.3

mozilla firefox esr 31.4

mozilla thunderbird 31.2

mozilla thunderbird 31.1.2

mozilla thunderbird 31.0

mozilla thunderbird

mozilla thunderbird 31.3

mozilla firefox 31.0

mozilla firefox 30.0

mozilla firefox 3.6.28

mozilla firefox 3.6.27

mozilla firefox 3.6.2

mozilla firefox 3.6.19

mozilla firefox 3.6.12

mozilla firefox 3.6.11

mozilla firefox 3.5.5

mozilla firefox 3.5.4

mozilla firefox 3.5.14

mozilla firefox 3.5.13

mozilla firefox 3.0.8

mozilla firefox 3.0.7

mozilla firefox 3.0.18

mozilla firefox 3.0.17

mozilla firefox 3.0.1

mozilla firefox 3.0

mozilla firefox 25.0.1

mozilla firefox 25.0

mozilla firefox 21.0

mozilla firefox 20.0.1

mozilla firefox 2.0.0.3

mozilla firefox 2.0.0.20

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.13

mozilla firefox 19.0.1

mozilla firefox 19.0

mozilla firefox 18.0.2

mozilla firefox 34.0.5

mozilla firefox 33.0

mozilla firefox 3.6.7

mozilla firefox 3.6.6

mozilla firefox 3.6.24

mozilla firefox 3.6.23

mozilla firefox 3.6.16

mozilla firefox 3.6.15

mozilla firefox 3.5.9

mozilla firefox 3.5.8

mozilla firefox 3.5.19

mozilla firefox 3.5.18

mozilla firefox 3.5.17

mozilla firefox 3.5.10

mozilla firefox 3.5.1

mozilla firefox 3.0.4

mozilla firefox 3.0.3

mozilla firefox 3.0.13

mozilla firefox 3.0.12

mozilla firefox 28.0

mozilla firefox 27.0.1

mozilla firefox 24.0

mozilla firefox 23.0.1

mozilla firefox 2.0.0.7

mozilla firefox 2.0.0.6

mozilla firefox 2.0.0.18

mozilla firefox 2.0.0.17

mozilla firefox 2.0.0.10

mozilla firefox 2.0.0.1

mozilla firefox 17.0.9

mozilla firefox 17.0.8

mozilla firefox 17.0.11

mozilla firefox 17.0.5

mozilla firefox 17.0.4

mozilla firefox 16.0.2

mozilla firefox 16.0.1

mozilla firefox 12.0

mozilla firefox 10.0.4

mozilla firefox 10.0.3

mozilla firefox 4.0

mozilla firefox 6.0.1

mozilla firefox 6.0.2

mozilla firefox 1.8

mozilla firefox 1.5.8

mozilla firefox 1.5.0.9

mozilla firefox 1.5.0.8

mozilla firefox 1.5.0.12

mozilla firefox 1.5.0.11

mozilla firefox 1.0.8

mozilla firefox 1.0.7

mozilla firefox 1.0

mozilla firefox 0.9.3

mozilla firefox 0.7

mozilla firefox 0.6.1

mozilla firefox 0.10

mozilla firefox 0.1

mozilla firefox 17.0.10

mozilla firefox 15.0

mozilla firefox 14.0.1

mozilla firefox 10.0.8

mozilla firefox 10.0.7

mozilla firefox 10.0.11

mozilla firefox 10.0.10

mozilla firefox 4.0.1

mozilla firefox 5.0

mozilla firefox 8.0

mozilla firefox 8.0.1

mozilla firefox 1.5.4

mozilla firefox 1.5.3

mozilla firefox 1.5.0.5

mozilla firefox 1.5.0.4

mozilla firefox 1.5

mozilla firefox 1.0.3

mozilla firefox 1.0.2

mozilla firefox 0.9

mozilla firefox 0.4

mozilla firefox 0.3

mozilla firefox 32.0

mozilla firefox 31.1.0

mozilla firefox 3.6.4

mozilla firefox 3.6.3

mozilla firefox 3.6.22

mozilla firefox 3.6.21

mozilla firefox 3.6.20

mozilla firefox 3.6.14

mozilla firefox 3.6.13

mozilla firefox 3.5.7

mozilla firefox 3.5.6

mozilla firefox 3.5.16

mozilla firefox 3.5.15

mozilla firefox 3.5

mozilla firefox 3.0.9

mozilla firefox 3.0.2

mozilla firefox 3.0.19

mozilla firefox 3.0.11

mozilla firefox 3.0.10

mozilla firefox 27.0

mozilla firefox 26.0

mozilla firefox 23.0

mozilla firefox 22.0

mozilla firefox 2.0.0.5

mozilla firefox 2.0.0.4

mozilla firefox 2.0.0.16

mozilla firefox 2.0.0.15

mozilla firefox 2.0

mozilla firefox 19.0.2

mozilla firefox 17.0.7

mozilla firefox 17.0.6

mozilla firefox 17.0.1

mozilla firefox 17.0

mozilla firefox 14.0

mozilla firefox 13.0.1

mozilla firefox 13.0

mozilla firefox 10.0.6

mozilla firefox 10.0.5

mozilla firefox 10.0.1

mozilla firefox 10.0

mozilla firefox 5.0.1

mozilla firefox 6.0

mozilla firefox 9.0

mozilla firefox 9.0.1

mozilla firefox 1.5.2

mozilla firefox 1.5.1

mozilla firefox 1.5.0.3

mozilla firefox 1.5.0.2

mozilla firefox 1.4.1

mozilla firefox 1.0.1

mozilla firefox 0.8

mozilla firefox 0.7.1

mozilla firefox 0.2

mozilla firefox 0.10.1

mozilla firefox

mozilla firefox 3.6.9

mozilla firefox 3.6.8

mozilla firefox 3.6.26

mozilla firefox 3.6.25

mozilla firefox 3.6.18

mozilla firefox 3.6.17

mozilla firefox 3.6.10

mozilla firefox 3.6

mozilla firefox 3.5.3

mozilla firefox 3.5.2

mozilla firefox 3.5.12

mozilla firefox 3.5.11

mozilla firefox 3.0.6

mozilla firefox 3.0.5

mozilla firefox 3.0.16

mozilla firefox 3.0.15

mozilla firefox 3.0.14

mozilla firefox 29.0.1

mozilla firefox 29.0

mozilla firefox 24.1.1

mozilla firefox 24.1

mozilla firefox 20.0

mozilla firefox 2.0.0.9

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.2

mozilla firefox 2.0.0.19

mozilla firefox 2.0.0.12

mozilla firefox 2.0.0.11

mozilla firefox 18.0.1

mozilla firefox 18.0

mozilla firefox 17.0.3

mozilla firefox 17.0.2

mozilla firefox 16.0

mozilla firefox 15.0.1

mozilla firefox 11.0

mozilla firefox 10.0.9

mozilla firefox 10.0.2

mozilla firefox 10.0.12

mozilla firefox 7.0

mozilla firefox 7.0.1

mozilla firefox 1.5.7

mozilla firefox 1.5.6

mozilla firefox 1.5.5

mozilla firefox 1.5.0.7

mozilla firefox 1.5.0.6

mozilla firefox 1.5.0.10

mozilla firefox 1.5.0.1

mozilla firefox 1.0.6

mozilla firefox 1.0.5

mozilla firefox 1.0.4

mozilla firefox 0.9.2

mozilla firefox 0.9.1

mozilla firefox 0.6

mozilla firefox 0.5

Vendor Advisories

Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic Updated firefox packages that fix multiple security issues are nowavailable for Red Hat Enterprise Linux 5, 6 and 7Red Hat Product Security has rated this update as having Critical securityimpact Common Vulnerabilit ...
Synopsis Important: thunderbird security update Type/Severity Security Advisory: Important Topic An updated thunderbird package that fixes multiple security issues is nowavailable for Red Hat Enterprise Linux 5 and 6Red Hat Product Security has rated this update as having Important securityimpact Common V ...
Multiple security issues have been found in Iceweasel, Debian's version of the Mozilla Firefox web browser: Multiple memory safety errors and implementation errors may lead to the execution of arbitrary code or information disclosure For the stable distribution (wheezy), these problems have been fixed in version 3150esr-1~deb7u1 For the unstabl ...
Several security issues were fixed in Thunderbird ...
USN-2505-1 introduced a regression in Firefox ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2015-11 Miscellaneous memory safety hazards (rv:360 / rv:315) Announced February 24, 2015 Reporter Mozilla Developers and Community Members Impact Critical Products Firefox, Firefox ESR, ...

Recent Articles

Firefox 36 swats bugs, adds HTTP2 and gets certifiably serious
The Register • Darren Pauli • 26 Feb 2015

Three big bads, six medium messes and 1024-bit certs all binned in one release

Mozilla has outfoxed three critical and six high severity flaws in its latest round of patches for its flagship browser. It stomps out memory safety bugs, exploitable use-after-free crashes, and a buffer overflow. Of the critical crashes, bad guys could potentially craft attacks targeting MP4 video playback through a buffer overflow in the libstagefright library (CVE-2015-0829). Another potential exploitable crash that is unlikely to be a threat in email clients where scripting was disabled ce...

References

NVD-CWE-noinfohttps://bugzilla.mozilla.org/show_bug.cgi?id=1117406http://www.mozilla.org/security/announce/2015/mfsa2015-11.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1128196https://bugzilla.mozilla.org/show_bug.cgi?id=1096138https://bugzilla.mozilla.org/show_bug.cgi?id=1119579https://bugzilla.mozilla.org/show_bug.cgi?id=1115776https://bugzilla.mozilla.org/show_bug.cgi?id=1123882https://bugzilla.mozilla.org/show_bug.cgi?id=1124018https://bugzilla.mozilla.org/show_bug.cgi?id=1107009https://bugzilla.mozilla.org/show_bug.cgi?id=1111243https://bugzilla.mozilla.org/show_bug.cgi?id=1111248http://www.securitytracker.com/id/1031791http://www.securitytracker.com/id/1031792http://www.securityfocus.com/bid/72742http://rhn.redhat.com/errata/RHSA-2015-0265.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0266.htmlhttp://www.ubuntu.com/usn/USN-2505-1http://www.debian.org/security/2015/dsa-3174http://www.ubuntu.com/usn/USN-2506-1http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00001.htmlhttp://www.debian.org/security/2015/dsa-3179http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00008.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0642.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00026.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00067.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttps://security.gentoo.org/glsa/201504-01http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlhttps://nvd.nist.govhttps://access.redhat.com/errata/RHSA-2015:0265https://usn.ubuntu.com/2506-1/https://www.debian.org/security/./dsa-3174