6.8
CVSSv2

CVE-2015-4510

Published: 24/09/2015 Updated: 22/12/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox prior to 41.0 allows remote malicious users to execute arbitrary code or cause a denial of service (use-after-free and application crash) by leveraging improper interaction between shared workers and the IndexedDB implementation.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
This update provides compatible packages for Firefox 41 ...
USN-2743-1 introduced a regression in Firefox ...
Mozilla Foundation Security Advisory 2015-104 Use-after-free with shared workers and IndexedDB Announced September 22, 2015 Reporter Looben Yang Impact Critical Products Firefox, SeaMonkey Fixed in ...
Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 410 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) by leveraging improper interaction between shared workers and the IndexedDB implementation ...