CVE-2015-4510 describes a race condition in Mozilla Firefox versions prior to 41.0, specifically within the WorkerPrivate::NotifyFeatures function. This vulnerability allows remote attackers to achieve arbitrary code execution or a denial of service (use-after-free and application crash) due to improper interaction between shared workers and the IndexedDB implementation. With a CVSS score of 6.8, it is considered a medium-severity vulnerability, requiring moderate attack complexity and potentially leading to partial confidentiality, integrity, and availability impacts. While it garnered some community discussion and media coverage upon disclosure, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 40.0.3CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.