6.4
CVSSv2

CVE-2015-4512

Published: 24/09/2015 Updated: 22/12/2016
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox prior to 41.0 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface creation followed by 16-bit color-depth surface display, which allows remote malicious users to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) by using a CANVAS element to trigger 2D rendering.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
This update provides compatible packages for Firefox 41 ...
USN-2743-1 introduced a regression in Firefox ...
Mozilla Foundation Security Advisory 2015-107 Out-of-bounds read during 2D canvas display on Linux 16-bit color depth systems Announced September 22, 2015 Reporter Francisco Alonso Impact Moderate Products Firefox, SeaMonkey ...
gfx/2d/DataSurfaceHelperscpp in Mozilla Firefox before 410 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface creation followed by 16-bit color-depth surface display, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) by using a CAN ...