CVE-2015-7212 PUBLISHED

Integer overflow in the mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by triggering a graphics operation that requires a large texture allocation.

EPSS 2.31% · 84.6th percentile

Risk Scores

EPSS Score
2.31%
84.6th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSthunderbird0, 1:24.0+build1-0ubuntu1, 1:24.0+build1-0ubuntu2
Ubuntu:14.04:LTSfirefox38.0+build3-0ubuntu0.14.04.1, 39.0+build5-0ubuntu0.14.04.1, 39.0.3+build2-0ubuntu0.14.04.1

Timeline

References

Open in Interactive Console →