CVE-2015-7201 describes multiple unspecified memory corruption vulnerabilities in the browser engine of Mozilla Firefox before version 43.0 and Firefox ESR 38.x before 38.5, affecting products like Fedora, Mozilla, and OpenSUSE. With a CVSS score of 10.0, this critical vulnerability allows remote attackers to cause a denial of service or potentially execute arbitrary code with low attack complexity and no authentication required. While no public exploit code is available via Metasploit, Nuclei, or ExploitDB, and it is not listed in the KEV catalog, the vulnerability garnered significant community discussion and media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
22CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:* | ||
23CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:* | ||
<= 42.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.