CVE-2015-2739 describes a critical memory access vulnerability within the ArrayBufferBuilder::append function in Mozilla Firefox, Firefox ESR, and Thunderbird, affecting versions before 39.0, 31.8/38.1, and 38.1 respectively. This flaw allows for unintended memory access with an unspecified impact and attack vectors. With a CVSS score of 10.0, it represents a critical risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not listed in the KEV catalog, the vulnerability received some community and media attention at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 38.1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:a:novell:suse_linux_enterprise_software_development_kit:12.0:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
14.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.