5
CVSSv2

CVE-2015-2729

Published: 06/07/2015 Updated: 28/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The AudioParamTimeline::AudioNodeInputValue function in the Web Audio implementation in Mozilla Firefox prior to 39.0 and Firefox ESR 38.x prior to 38.1 does not properly calculate an oscillator rendering range, which allows remote malicious users to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox esr 31.6.0

mozilla firefox esr 31.5.3

mozilla firefox esr 31.1.1

mozilla firefox esr 31.1.0

mozilla firefox esr 31.5.2

mozilla firefox esr 31.5.1

mozilla firefox esr 31.1

mozilla firefox esr 31.0

mozilla firefox esr 31.5

mozilla firefox esr 31.4

mozilla firefox esr 31.3.0

mozilla firefox esr 38.0

mozilla firefox esr 31.7.0

mozilla firefox esr 31.3

mozilla firefox esr 31.2

mozilla thunderbird

mozilla firefox

oracle solaris 11.3

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2015-62 Out-of-bound read while computing an oscillator rendering range in Web Audio Announced July 2, 2015 Reporter Holger Fuhrmannek Impact Moderate Products Firefox, Firefox ESR, Firef ...
The AudioParamTimeline::AudioNodeInputValue function in the Web Audio implementation in Mozilla Firefox before 390 and Firefox ESR 38x before 381 does not properly calculate an oscillator rendering range, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspec ...