HIGH🇵🇱 Wersja polska

CVE-2015-2738

CVSS 10.0v2.0pub. 2015-07-06upd. 2026-05-06

The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.

CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
  • Canonical Ubuntu

    OS
    Canonical
    12.0414.0414.1015.04
  • Debian

    OS
    Debian
    7.08.0
  • Mozilla Firefox

    APP
    Mozilla
    31.031.1.031.1.131.3.031.5.131.5.231.5.338.0≤ 38.1.0
  • Mozilla Firefox Esr

    APP
    Mozilla
    31.131.231.331.431.531.6.031.7.0
  • Mozilla Thunderbird

    APP
    Mozilla
    ≤ 38.0.1
  • Oracle Solaris

    OS
    Oracle
    11.3
  • SUSE Linux Enterprise Desktop

    OS
    Suse
    12
  • SUSE Linux Enterprise Server

    OS
    Suse
    11
  • SUSE Linux Enterprise Software Development Kit

    OS
    Suse
    12
  • SUSE Linux Enterprise Server

    OS
    Suse
    12
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Deserialization
CWE
References

Related vulnerabilities

CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same product

GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2025-49113CRITICAL9.9⚠ KEVPL ✓same product

RCE przez deserializację PHP w Roundcube Webmail (parametr _from)

CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓same product

Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)

CVE-2025-24201CRITICAL10.0⚠ KEVPL ✓same product

Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki