5.1
CVSSv2

CVE-2015-4507

Published: 24/09/2015 Updated: 22/12/2016
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The SavedStacks class in the JavaScript implementation in Mozilla Firefox prior to 41.0, when the Debugger API is enabled, allows remote malicious users to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbitrary code via a crafted web site.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
This update provides compatible packages for Firefox 41 ...
USN-2743-1 introduced a regression in Firefox ...
Mozilla Foundation Security Advisory 2015-102 Crash when using debugger with SavedStacks in JavaScript Announced September 22, 2015 Reporter Spandan Veggalam Impact Moderate Products Firefox, Firefox OS, SeaMonkey Fixed ...