CVE-2015-0827 PUBLISHED

Heap-based buffer overflow in the mozilla::gfx::CopyRect function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to obtain sensitive information from uninitialized process memory via a malformed SVG graphic.

EPSS 1.00% · 76.8th percentile

Risk Scores

EPSS Score
1.00%
76.8th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSthunderbird0, 1:24.0+build1-0ubuntu1, 1:24.0+build1-0ubuntu2
Ubuntu:14.04:LTSfirefox0, 35.0.1+build1-0ubuntu0.14.04.1, 24.0+build1-0ubuntu1

Timeline

References

Open in Interactive Console →