CVE-2015-2734 describes an uninitialized memory read vulnerability in the CairoTextureClientD3D9::BorrowDrawTarget function within the Direct3D 9 implementation of Mozilla Firefox, Firefox ESR, and Thunderbird. This flaw allows attackers to read data from uninitialized memory, with unspecified impact and attack vectors. Rated with a critical CVSS score of 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C), it indicates a network-exploitable vulnerability with complete confidentiality, integrity, and availability impact, though its EPSS and FAUCET scores suggest a lower likelihood of exploitation in practice. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed in the KEV catalog, and community discussion and media coverage are minimal, indicating it is not actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_desktop:12:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_server:11:sp4:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_software_development_kit:12:*:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:o:suse:suse_linux_enterprise_server:12:*:*:*:*:*:*:* | ||
31.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:31.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.