6.4
CVSSv2

CVE-2015-4504

Published: 24/09/2015 Updated: 22/12/2016
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

The lut_inverse_interp16 function in the QCMS library in Mozilla Firefox prior to 41.0 allows remote malicious users to obtain sensitive information or cause a denial of service (buffer over-read and application crash) via crafted attributes in the ICC 4 profile of an image.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
This update provides compatible packages for Firefox 41 ...
USN-2743-1 introduced a regression in Firefox ...
Mozilla Foundation Security Advisory 2015-98 Out of bounds read in QCMS library with ICC V4 profile attributes Announced September 22, 2015 Reporter Felix Gröbert Impact Moderate Products Firefox, SeaMonkey Fixed in ...