Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code via crafted SVG graphics data in conjunction with a crafted Cascading Style Sheets (CSS) token sequence.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2015-05-14 03:59
Updated : 2018-10-30 09:27
NVD link : CVE-2015-2710
Mitre link : CVE-2015-2710
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
mozilla
- firefox_esr
- thunderbird
- firefox
novell
- suse_linux_enterprise_server
- suse_linux_enterprise_desktop
- suse_linux_enterprise_software_development_kit
opensuse
- opensuse