CVE-2015-0831: Use After Free
Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0831?
CVE-2015-0831 is classified as a critical vulnerability that allows for arbitrary code execution or denial of service through heap memory corruption.
How do I fix CVE-2015-0831?
To fix CVE-2015-0831, upgrade to Firefox version 36.0 or later, Mozilla Thunderbird version 31.5 or later, or Firefox ESR version 31.5 or later.
What products are affected by CVE-2015-0831?
Affected products include Mozilla Firefox versions prior to 36.0 and versions of Mozilla Thunderbird before 31.5.
Is there a workaround for CVE-2015-0831?
Disabling JavaScript may serve as a temporary workaround for CVE-2015-0831, but it is not a complete solution.
What impact does CVE-2015-0831 have on users?
CVE-2015-0831 can potentially allow remote attackers to execute arbitrary code on a user's machine, compromising system security.