CVE-2015-0826: Buffer Overflow
The nsTransformedTextRun::SetCapitalization function in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read of heap memory) via a crafted Cascading Style Sheets (CSS) token sequence that triggers a restyle or reflow operation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0826?
The severity of CVE-2015-0826 is classified as critical due to its potential to allow remote code execution and denial of service.
How do I fix CVE-2015-0826?
To fix CVE-2015-0826, update Mozilla Firefox to version 36.0 or later.
What versions of Firefox are affected by CVE-2015-0826?
CVE-2015-0826 affects Mozilla Firefox versions prior to 36.0, including numerous older versions.
What type of vulnerability is CVE-2015-0826?
CVE-2015-0826 is a heap buffer overflow vulnerability that can lead to arbitrary code execution.
Can CVE-2015-0826 be exploited through CSS?
Yes, CVE-2015-0826 can be exploited by attackers via a crafted Cascading Style Sheets (CSS) token sequence.