CVE-2015-2731: Use After Free
Last updated 24 July 2024
Other sources
Use-after-free vulnerability in the CSPService::ShouldLoad function in the microtask implementation in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allows remote attackers to execute arbitrary code by leveraging client-side JavaScript that triggers removal of a DOM object on the basis of a Content Policy.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-2731?
CVE-2015-2731 is a use-after-free vulnerability in the CSPService::ShouldLoad function in Mozilla Firefox and Thunderbird, allowing remote attackers to execute arbitrary code.
How severe is CVE-2015-2731?
CVE-2015-2731 is classified as a critical vulnerability with a severity score of 10.
Which software versions are affected by CVE-2015-2731?
Mozilla Firefox versions before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird versions before 38.1 are affected by CVE-2015-2731.
How can CVE-2015-2731 be fixed?
To fix CVE-2015-2731, update Mozilla Firefox to version 39.0 or later, Firefox ESR to version 38.1 or later, and Thunderbird to version 38.1 or later.
Where can I find more information about CVE-2015-2731?
More information about CVE-2015-2731 can be found on the CVE website at https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2731 and the Mozilla Security Advisories website at https://www.mozilla.org/en-US/security/advisories/mfsa2015-63/.