CVE-2015-2716 describes a buffer overflow vulnerability in the XML parser of Mozilla Firefox (before 38.0), Firefox ESR (before 31.7), and Thunderbird (before 31.7), also affecting products from Novell, OpenSUSE, and Oracle. This vulnerability carries a high CVSS score of 7.5, indicating it can be exploited remotely with low complexity to achieve partial confidentiality, integrity, and availability impacts. While no active exploitation (KEV) or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, the vulnerability received some community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 37.0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:12.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:novell:suse_linux_enterprise_desktop:12.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:novell:suse_linux_enterprise_server:12.0:*:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.