CVE Database
/

CVE-2015-2710

Back to search

CVE-2015-2710

Published: May 14, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code via crafted SVG graphics data in conjunction with a crafted Cascading Style Sheets (CSS) token sequence.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-2602-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2015:0988
vendor-advisory
x_refsource_REDHAT
74611
vdb-entry
x_refsource_BID
openSUSE-SU-2015:0892
vendor-advisory
x_refsource_SUSE
DSA-3264
vendor-advisory
x_refsource_DEBIAN
DSA-3260
vendor-advisory
x_refsource_DEBIAN
SUSE-SU-2015:0978
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2015:0934
vendor-advisory
x_refsource_SUSE
USN-2603-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2015:0960
vendor-advisory
x_refsource_SUSE
RHSA-2015:1012
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2015:1266
vendor-advisory
x_refsource_SUSE
GLSA-201605-06
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now