CVE-2015-0817: Medium severity firefox vulnerability
The asm.js implementation in Mozilla Firefox before 36.0.3, Firefox ESR 31.x before 31.5.2, and SeaMonkey before 2.33.1 does not properly determine the cases in which bounds checking may be safely skipped during JIT compilation and heap access, which allows remote attackers to read or write to unintended memory locations, and consequently execute arbitrary code, via crafted JavaScript.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0817?
CVE-2015-0817 has a medium severity rating as it can lead to unauthorized memory access.
How do I fix CVE-2015-0817?
To mitigate CVE-2015-0817, users should update to the latest versions of Mozilla Firefox, Firefox ESR, or SeaMonkey.
Which versions are affected by CVE-2015-0817?
CVE-2015-0817 affects Mozilla Firefox versions prior to 36.0.3, Firefox ESR versions before 31.5.2, and SeaMonkey versions before 2.33.1.
Can CVE-2015-0817 be exploited remotely?
Yes, CVE-2015-0817 can be exploited by remote attackers to read or write memory without proper bounds checking.
Is CVE-2015-0817 fixed in newer versions?
Yes, CVE-2015-0817 has been addressed and patched in versions of Mozilla Firefox, Firefox ESR, and SeaMonkey released after the specified versions.