Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code via crafted SVG graphics data in conjunction with a crafted Cascading Style Sheets (CSS) token sequence.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2015-05-14 10:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-2710
Mitre link : CVE-2015-2710
CVE.ORG link : CVE-2015-2710
JSON object : View
Products Affected
opensuse
- opensuse
mozilla
- thunderbird
- firefox_esr
- firefox
novell
- suse_linux_enterprise_server
- suse_linux_enterprise_software_development_kit
- suse_linux_enterprise_desktop
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer