CVE-2015-7189: Buffer Overflow
Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7189?
CVE-2015-7189 has a high severity rating due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2015-7189?
To fix CVE-2015-7189, upgrade to Mozilla Firefox version 42.0 or later, or Firefox ESR version 38.4 or later.
Which versions of Firefox are affected by CVE-2015-7189?
CVE-2015-7189 affects Firefox versions prior to 42.0 and Firefox ESR versions prior to 38.4.
What kind of attacks can CVE-2015-7189 enable?
CVE-2015-7189 can enable remote code execution or cause a denial of service through a heap-based buffer overflow.
Is CVE-2015-7189 specific to a particular element in web applications?
Yes, CVE-2015-7189 exploits vulnerabilities in vectors involving the CANVAS element and crafted JavaScript code.