CVE-2015-0828: Double Free
Double free vulnerability in the nsXMLHttpRequest::GetResponse function in Mozilla Firefox before 36.0, when a nonstandard memory allocator is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted JavaScript code that makes an XMLHttpRequest call with zero bytes of data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0828?
CVE-2015-0828 has been classified as a critical severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2015-0828?
The recommended fix for CVE-2015-0828 is to upgrade Mozilla Firefox to version 36.0 or later.
What is the impact of CVE-2015-0828?
The impact of CVE-2015-0828 can lead to arbitrary code execution or a denial of service through heap memory corruption.
Which versions of Mozilla Firefox are affected by CVE-2015-0828?
CVE-2015-0828 affects all versions of Mozilla Firefox prior to 36.0.
Is there a workaround for CVE-2015-0828?
There are no effective workarounds for CVE-2015-0828 other than updating to a secure version.