CVE-2015-0835 describes multiple unspecified vulnerabilities within the browser engine of Mozilla Firefox, specifically versions prior to 36.0. These flaws could be remotely triggered by attackers, leading to a denial of service through memory corruption and application crashes, or potentially enabling arbitrary code execution. With a CVSS score of 7.5 (High), the vulnerability is easily exploitable over a network with low attack complexity, posing risks of partial confidentiality, integrity, and availability impacts. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, the vulnerability received some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 35.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:0.1:*:*:*:*:*:*:* | ||
0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:0.2:*:*:*:*:*:*:* | ||
0.3CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:0.3:*:*:*:*:*:*:* | ||
0.4CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.