CVE-2015-7174: Buffer Overflow
The nsAttrAndChildArray::GrowBy function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7174?
CVE-2015-7174 is classified as having the potential for denial of service due to memory corruption.
How do I fix CVE-2015-7174?
To fix CVE-2015-7174, update your Mozilla Firefox or Firefox ESR to version 41.0 or later.
What versions of Mozilla Firefox are affected by CVE-2015-7174?
CVE-2015-7174 affects Mozilla Firefox versions before 41.0 and Firefox ESR versions before 38.3.
What could happen if I am still using a vulnerable version related to CVE-2015-7174?
Using a vulnerable version could allow remote attackers to crash the application or possibly cause other unspecified impacts.
Is CVE-2015-7174 a remote code execution vulnerability?
CVE-2015-7174 is not classified as a remote code execution vulnerability; it primarily causes denial of service.