CVE-2015-0817 describes a critical vulnerability in the asm.js implementation of Mozilla Firefox, Firefox ESR, and SeaMonkey. This flaw allows remote attackers to bypass bounds checking during JIT compilation and heap access, leading to unintended memory reads or writes and ultimately arbitrary code execution. With a CVSS score of 6.8, it presents a medium-complexity attack vector (AV:N/AC:M/Au:N) that can result in partial confidentiality, integrity, and availability impacts. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) is available, the vulnerability was disclosed following Pwn2Own 2015, indicating it was exploitable in the wild at that time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 36.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
31.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:31.0:*:*:*:*:*:*:* | ||
31.1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:31.1.0:*:*:*:*:*:*:* | ||
31.1.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:31.1.1:*:*:*:*:*:*:* | ||
31.3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:31.3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.