CVE-2015-2710

Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code via crafted SVG graphics data in conjunction with a crafted Cascading Style Sheets (CSS) token sequence.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00054.html
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
http://lists.opensuse.org/opensuse-updates/2015-05/msg00036.html
http://rhn.redhat.com/errata/RHSA-2015-0988.html
http://rhn.redhat.com/errata/RHSA-2015-1012.html
http://www.debian.org/security/2015/dsa-3260
http://www.debian.org/security/2015/dsa-3264
http://www.mozilla.org/security/announce/2015/mfsa2015-48.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.securityfocus.com/bid/74611
http://www.ubuntu.com/usn/USN-2602-1
http://www.ubuntu.com/usn/USN-2603-1
https://bugzilla.mozilla.org/show_bug.cgi?id=1149542
https://security.gentoo.org/glsa/201605-06
https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird31.7
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00054.html
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
http://lists.opensuse.org/opensuse-updates/2015-05/msg00036.html
http://rhn.redhat.com/errata/RHSA-2015-0988.html
http://rhn.redhat.com/errata/RHSA-2015-1012.html
http://www.debian.org/security/2015/dsa-3260
http://www.debian.org/security/2015/dsa-3264
http://www.mozilla.org/security/announce/2015/mfsa2015-48.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.securityfocus.com/bid/74611
http://www.ubuntu.com/usn/USN-2602-1
http://www.ubuntu.com/usn/USN-2603-1
https://bugzilla.mozilla.org/show_bug.cgi?id=1149542
https://security.gentoo.org/glsa/201605-06
https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird31.7
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:mozilla:firefox:31.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.3.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.5.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.5.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.5.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.6.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:12.0:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_desktop:12.0:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_server:12.0:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:27

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html - () http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html -
References () http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00054.html - () http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00054.html -
References () http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00000.html - () http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00000.html -
References () http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html - () http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html -
References () http://lists.opensuse.org/opensuse-updates/2015-05/msg00036.html - () http://lists.opensuse.org/opensuse-updates/2015-05/msg00036.html -
References () http://rhn.redhat.com/errata/RHSA-2015-0988.html - () http://rhn.redhat.com/errata/RHSA-2015-0988.html -
References () http://rhn.redhat.com/errata/RHSA-2015-1012.html - () http://rhn.redhat.com/errata/RHSA-2015-1012.html -
References () http://www.debian.org/security/2015/dsa-3260 - () http://www.debian.org/security/2015/dsa-3260 -
References () http://www.debian.org/security/2015/dsa-3264 - () http://www.debian.org/security/2015/dsa-3264 -
References () http://www.mozilla.org/security/announce/2015/mfsa2015-48.html - Vendor Advisory () http://www.mozilla.org/security/announce/2015/mfsa2015-48.html - Vendor Advisory
References () http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html - () http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html -
References () http://www.securityfocus.com/bid/74611 - () http://www.securityfocus.com/bid/74611 -
References () http://www.ubuntu.com/usn/USN-2602-1 - () http://www.ubuntu.com/usn/USN-2602-1 -
References () http://www.ubuntu.com/usn/USN-2603-1 - () http://www.ubuntu.com/usn/USN-2603-1 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1149542 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1149542 -
References () https://security.gentoo.org/glsa/201605-06 - () https://security.gentoo.org/glsa/201605-06 -
References () https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird31.7 - () https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird31.7 -

22 Oct 2024, 13:54

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox_esr:31.5.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:31.5.1:*:*:*:*:*:*:*

21 Oct 2024, 13:55

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox_esr:31.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.0:*:*:*:*:*:*:*

21 Oct 2024, 13:11

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox_esr:31.3.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.5.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.5.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.5.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.3.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.5.3:*:*:*:*:*:*:*

Information

Published : 2015-05-14 10:59

Updated : 2024-11-21 02:27


NVD link : CVE-2015-2710

Mitre link : CVE-2015-2710

CVE.ORG link : CVE-2015-2710


JSON object : View

Products Affected

novell

  • suse_linux_enterprise_desktop
  • suse_linux_enterprise_software_development_kit
  • suse_linux_enterprise_server

opensuse

  • opensuse

mozilla

  • thunderbird
  • firefox
  • firefox_esr
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer