CVE-2015-2737 describes a critical vulnerability in the rx::d3d11::SetBufferData function within the Direct3D 11 implementation of Mozilla Firefox, Firefox ESR, and Thunderbird, where uninitialized memory is read. This flaw affects various versions of these Mozilla products, as well as distributions from Canonical, Debian, Oracle, and SUSE. With a CVSS score of 10.0, it represents a severe risk, allowing for complete compromise of confidentiality, integrity, and availability with low attack complexity and no authentication required. While no public exploit code is available in Metasploit, Nuclei, or ExploitDB, and it is not listed in CISA's KEV catalog, the vulnerability garnered significant media attention and community discussion at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
31.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:31.0:*:*:*:*:*:*:* | ||
31.1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:31.1.0:*:*:*:*:*:*:* | ||
31.1.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:31.1.1:*:*:*:*:*:*:* | ||
31.3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:31.3.0:*:*:*:*:*:*:* | ||
31.5.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:31.5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.