CVE-2015-0813 is a use-after-free vulnerability in the AppendElements function affecting Mozilla Firefox, Firefox ESR, and Thunderbird on Linux when using the Fluendo MP3 plugin for GStreamer. This flaw allows remote attackers to execute arbitrary code or cause a denial of service via a crafted MP3 file. With a CVSS score of 5.1 (medium), it requires high attack complexity (AC:H) but can lead to partial confidentiality, integrity, and availability impacts (C:P/I:P/A:P). There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 31.5.3CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
<= 36.0.4CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
<= 31.5CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.