Описание
Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code.
Релиз | Статус | Примечание |
---|---|---|
devel | released | 42.0+build2-0ubuntu1 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [42.0+build2-0ubuntu0.14.04.1]] |
precise | released | 42.0+build2-0ubuntu0.12.04.1 |
trusty | released | 42.0+build2-0ubuntu0.14.04.1 |
trusty/esm | DNE | trusty was released [42.0+build2-0ubuntu0.14.04.1] |
upstream | released | 42.0 |
vivid | released | 42.0+build2-0ubuntu0.15.04.1 |
wily | released | 42.0+build2-0ubuntu0.15.10.1 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | released | 1:38.4.0+build3-0ubuntu1 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [1:38.4.0+build3-0ubuntu0.14.04.1]] |
precise | released | 1:38.4.0+build3-0ubuntu0.12.04.1 |
trusty | released | 1:38.4.0+build3-0ubuntu0.14.04.1 |
trusty/esm | DNE | trusty was released [1:38.4.0+build3-0ubuntu0.14.04.1] |
upstream | released | 38.4.0 |
vivid | released | 1:38.4.0+build3-0ubuntu0.15.04.1 |
wily | released | 1:38.4.0+build3-0ubuntu0.15.10.1 |
Показывать по
EPSS
6.8 Medium
CVSS2
Связанные уязвимости
Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code.
Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code.
Race condition in the JPEGEncoder function in Mozilla Firefox before 4 ...
Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code.
Уязвимость браузеров Firefox и Firefox ESR, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
EPSS
6.8 Medium
CVSS2