Unrated severityNVD Advisory· Published Jul 6, 2015· Updated May 6, 2026
CVE-2015-2733
CVE-2015-2733
Description
Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a dedicated worker.
Affected products
20cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <=38.1.0
- cpe:2.3:a:mozilla:firefox:31.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:31.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:31.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:31.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:31.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:31.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:31.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.1:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:mozilla:firefox_esr:31.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox_esr:31.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox_esr:31.3:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox_esr:31.4:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox_esr:31.5:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox_esr:31.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox_esr:31.7.0:*:*:*:*:*:*:*
cpe:2.3:o:novell:suse_linux_enterprise_desktop:11:sp4:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:novell:suse_linux_enterprise_desktop:11:sp4:*:*:*:*:*:*
- cpe:2.3:o:novell:suse_linux_enterprise_desktop:12.0:*:*:*:*:*:*:*
- cpe:2.3:o:novell:suse_linux_enterprise_server:12.0:*:*:*:*:*:*:*
- cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
16- lists.opensuse.org/opensuse-security-announce/2015-07/msg00033.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2015-07/msg00034.htmlnvdThird Party Advisory
- www.mozilla.org/security/announce/2015/mfsa2015-65.htmlnvdVendor Advisory
- www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlnvdThird Party Advisory
- www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlnvdThird Party Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue Tracking
- lists.opensuse.org/opensuse-security-announce/2015-07/msg00025.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.htmlnvd
- rhn.redhat.com/errata/RHSA-2015-1207.htmlnvd
- www.securityfocus.com/bid/75541nvd
- www.securitytracker.com/id/1032783nvd
- www.securitytracker.com/id/1032784nvd
- www.ubuntu.com/usn/USN-2656-1nvd
- www.ubuntu.com/usn/USN-2656-2nvd
- security.gentoo.org/glsa/201512-10nvd
News mentions
0No linked articles in our index yet.