CVE-2015-7199 PUBLISHED

The (1) AddWeightedPathSegLists and (2) SVGPathSegListSMILType::Interpolate functions in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 lack status checking, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted SVG document.

EPSS 2.53% · 85.3th percentile

Risk Scores

EPSS Score
2.53%
85.3th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSthunderbird0, 1:24.0+build1-0ubuntu1, 1:24.0+build1-0ubuntu2
Ubuntu:14.04:LTSfirefox37.0.2+build1-0ubuntu0.14.04.1, 38.0+build3-0ubuntu0.14.04.1, 39.0+build5-0ubuntu0.14.04.1

Timeline

References

Open in Interactive Console →