6.8
CVSSv2

CVE-2015-2717

Published: 14/05/2015 Updated: 30/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in libstagefright in Mozilla Firefox prior to 38.0 allows remote malicious users to execute arbitrary code or cause a denial of service (heap-based buffer overflow and out-of-bounds read) via an MP4 video file containing invalid metadata.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

opensuse opensuse 13.1

opensuse opensuse 13.2

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2015-55 Buffer overflow and out-of-bounds read while parsing MP4 video metadata Announced May 12, 2015 Reporter lafintel Impact High Products Firefox, Firefox OS, SeaMonkey Fixed in ...
Integer overflow in libstagefright in Mozilla Firefox before 380 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and out-of-bounds read) via an MP4 video file containing invalid metadata ...