CVE-2015-2726 describes multiple unspecified memory corruption vulnerabilities within the browser engine of Mozilla Firefox versions prior to 39.0, also impacting products from Novell and Oracle. These vulnerabilities carry a critical CVSS score of 10.0, indicating a network-exploitable, low-complexity attack that could lead to complete compromise of confidentiality, integrity, and availability, including denial of service or arbitrary code execution. While the vulnerability is not listed on the CISA KEV catalog and no public exploit code (Metasploit, Nuclei, ExploitDB) is readily available, it garnered significant community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.3CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:* | ||
<= 38.1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:12.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:novell:suse_linux_enterprise_desktop:12.0:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:o:novell:suse_linux_enterprise_server:11:sp4:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.