HIGH · 10.0

CVE-2015-2740

Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote...

Vulnerability Description

Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote attackers to cause a denial of service or have unspecified other impact via unknown vectors.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MozillaThunderbird<= 38.0.1
MozillaFirefox31.0
MozillaFirefox Esr31.1
NovellSuse Linux Enterprise Software Development Kit12.0
CanonicalUbuntu Linux12.04
DebianDebian Linux7.0
NovellSuse Linux Enterprise Desktop12.0
NovellSuse Linux Enterprise Server11
OracleSolaris11.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-2740?

CVE-2015-2740 is a vulnerability with a CVSS score of 10.0 (HIGH). Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote...

How severe is CVE-2015-2740?

CVE-2015-2740 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-2740?

Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Thunderbird, Mozilla Firefox, Mozilla Firefox Esr, Novell Suse Linux Enterprise Software Development Kit, Canonical Ubuntu Linux.