CVE-2015-7176: Buffer Overflow
The AnimationThread function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 uses an incorrect argument to the sscanf function, which might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via unknown vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7176?
CVE-2015-7176 has a medium severity rating due to its potential to cause denial of service.
How do I fix CVE-2015-7176?
To fix CVE-2015-7176, update your Mozilla Firefox or Firefox ESR to version 41.0 or later, or to version 38.3 or later respectively.
What could happen if I do not address CVE-2015-7176?
If CVE-2015-7176 is not addressed, it may lead to application crashes or other unspecified impacts.
Which versions of Firefox are affected by CVE-2015-7176?
CVE-2015-7176 affects Mozilla Firefox versions below 41.0 and Firefox ESR versions before 38.3.
Is CVE-2015-7176 a remote code execution vulnerability?
CVE-2015-7176 is not classified as a remote code execution vulnerability but may cause a denial of service.