7.5
CVSSv2

CVE-2015-2712

Published: 14/05/2015 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The asm.js implementation in Mozilla Firefox prior to 38.0 does not properly determine heap lengths during identification of cases in which bounds checking may be safely skipped, which allows remote malicious users to trigger out-of-bounds write operations and possibly execute arbitrary code, or trigger out-of-bounds read operations and possibly obtain sensitive information from process memory, via crafted JavaScript.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

opensuse opensuse 13.1

opensuse opensuse 13.2

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2015-50 Out-of-bounds read and write in asmjs validation Announced May 12, 2015 Reporter Dougall Johnson Impact Critical Products Firefox, SeaMonkey Fixed in ...
The asmjs implementation in Mozilla Firefox before 380 does not properly determine heap lengths during identification of cases in which bounds checking may be safely skipped, which allows remote attackers to trigger out-of-bounds write operations and possibly execute arbitrary code, or trigger out-of-bounds read operations and possibly obtain sen ...