CVE-2015-2738 describes a critical vulnerability in the YCbCrImageDataDeserializer::ToDataSourceSurface function within Mozilla Firefox (versions before 39.0, ESR 31.x before 31.8, and 38.x before 38.1) and Thunderbird (before 38.1). This flaw involves reading data from uninitialized memory, impacting products from Canonical, Debian, Mozilla, Oracle, and SUSE. With a CVSS score of 10.0, this vulnerability is highly severe, indicating a network-based attack with low complexity that could lead to complete compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it's not on the KEV catalog, the vulnerability garnered significant media attention and community discussion at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
14.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:* | ||
15.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:o:suse:linux_enterprise_desktop:12:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.