Unrated severityNVD Advisory· Published May 14, 2015· Updated May 6, 2026
CVE-2015-2716
CVE-2015-2716
Description
Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.
Affected products
7- osv-coords7 versionspkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012
< 128.5.1-1.1+ 6 more
- (no CPE)range: < 128.5.1-1.1
- (no CPE)range: < 50.1.0-1.1
- (no CPE)range: < 45.5.1-1.1
- (no CPE)range: < 31.7.0esr-34.1
- (no CPE)range: < 31.7.0esr-34.1
- (no CPE)range: < 31.7.0esr-34.1
- (no CPE)range: < 31.7.0esr-34.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
20- lists.opensuse.org/opensuse-security-announce/2015-05/msg00054.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-updates/2015-05/msg00036.htmlnvdThird Party Advisory
- www.mozilla.org/security/announce/2015/mfsa2015-54.htmlnvdVendor Advisory
- www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlnvdThird Party Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue Tracking
- lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-06/msg00000.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-0988.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-1012.htmlnvd
- www.debian.org/security/2015/dsa-3260nvd
- www.debian.org/security/2015/dsa-3264nvd
- www.securityfocus.com/bid/74611nvd
- www.ubuntu.com/usn/USN-2602-1nvd
- www.ubuntu.com/usn/USN-2603-1nvd
- hg.mozilla.org/releases/mozilla-esr31/rev/2f3e78643f5cnvd
- kc.mcafee.com/corporate/indexnvd
- security.gentoo.org/glsa/201605-06nvd
- www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/nvd
- www.tenable.com/security/tns-2016-20nvd
News mentions
0No linked articles in our index yet.