10

CVE-2015-2738

The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CanonicalUbuntu Linux Version12.04 SwEditionlts
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version14.10
CanonicalUbuntu Linux Version15.04
SuseLinux Enterprise Server Version11 Updatesp4
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
MozillaFirefox Version <= 38.1.0
MozillaFirefox Version31.0
MozillaFirefox Version31.1.0
MozillaFirefox Version31.1.1
MozillaFirefox Version31.3.0
MozillaFirefox Version31.5.1
MozillaFirefox Version31.5.2
MozillaFirefox Version31.5.3
MozillaFirefox Version38.0
MozillaFirefox ESR Version31.1
MozillaFirefox ESR Version31.2
MozillaFirefox ESR Version31.3
MozillaFirefox ESR Version31.4
MozillaFirefox ESR Version31.5
MozillaFirefox ESR Version31.6.0
MozillaFirefox ESR Version31.7.0
MozillaThunderbird Version <= 38.0.1
OracleSolaris Version11.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.95% 0.753
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C