CVE-2015-2716

Description

Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.

Risk Information

Base Score
10.0
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
5.614

Associated Vulnerability

VulnerabilityOS Platform
Update for SeaMonkey (2.35)Windows
Update for Mozilla Firefox ESR (38.1.0)Windows
Update for Mozilla Firefox ESR (38.1.1)Windows
Update for Mozilla Firefox ESR (38.2)Windows
Update for Mozilla Firefox ESR (38.2.1)Windows
Update for Mozilla Firefox ESR (38.3.0)Windows
Update for Mozilla Firefox ESR (38.4.0)Windows
Update for Mozilla Firefox ESR (38.5.0)Windows
Update for Mozilla Firefox ESR (38.5.1)Windows
Update for Mozilla Firefox ESR (38.5.2)Windows
Update for Mozilla Firefox ESR (38.6.0)Windows
Update for Mozilla Firefox ESR (38.6.1)Windows
Update for Mozilla Firefox ESR (38.7.0)Windows
Multiple Vulnerabilities are affected in Mozilla Firefox 37.0.2Windows
Multiple vulnerabilities are fixed in IBM HTTP 8.5.5.7Windows
Multiple vulnerabilities are fixed in IBM HTTP 8.0.0.12Windows
Multiple vulnerabilities are fixed in IBM HTTP 8.0.0.9Windows
Multiple vulnerabilities are fixed in IBM HTTP 7.0.0.33Windows
Multiple vulnerabilities are fixed in IBM HTTP 6.1.0.47Windows
Vulnerabilities CVE-2015-4947,CVE-2015-2716,CVE-2015-1283 are fixed in IBM HTTP 8.5.5.4Windows
Multiple vulnerabilities are fixed in IBM HTTP 7.0.0.39Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR (x64) 31.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR (x64) 31.2Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR (x64) 31.3Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR (x64) 31.4Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR (x64) 31.5Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR 31.1Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR 31.2Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR 31.3Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR 31.4Windows
Multiple Vulnerabilities are affected in Mozilla Firefox ESR 31.5Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.23Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.30Windows
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (138.0)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (138.0.1)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (138.0.3)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (138.0.4)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac 2.2Mac
Vulnerabilities CVE-2015-2716,CVE-2015-2713,CVE-2015-2710,CVE-2015-2708 are fixed in Mozilla Thunderbird For Mac 31.7Mac
Vulnerabilities CVE-2015-2716,CVE-2015-2713,CVE-2015-2710,CVE-2015-2708 are fixed in Mozilla Thunderbird For Mac 38.0.1Mac
Vulnerabilities CVE-2015-2716,CVE-2015-2713,CVE-2015-2710,CVE-2015-2708,CVE-2015-2709 are fixed in Mozilla Firefox For Mac 31.7Mac
(RHSA-2020:1011) expat security update expat-2.1.0-11.el7.i686.rpmLinux
(RHSA-2020:1011) expat security update expat-2.1.0-11.el7.x86_64.rpmLinux
(RHSA-2020:1011) expat security update expat-devel-2.1.0-11.el7.i686.rpmLinux
(RHSA-2020:1011) expat security update expat-devel-2.1.0-11.el7.x86_64.rpmLinux
(RHSA-2020:1011) expat security update expat-static-2.1.0-11.el7.i686.rpmLinux
(RHSA-2020:1011) expat security update expat-static-2.1.0-11.el7.x86_64.rpmLinux
(CESA-2020:1011) expat security update expat-2.1.0-11.el7.x86_64.rpmLinux
(CESA-2020:1011) expat security update expat-devel-2.1.0-11.el7.x86_64.rpmLinux
(CESA-2020:1011) expat security update expat-static-2.1.0-11.el7.x86_64.rpmLinux
Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2015-2716)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-301494Update for SeaMonkey (2.35)
PATCH-302079Update for Mozilla Firefox ESR (38.1.0)
PATCH-302171Update for Mozilla Firefox ESR (38.1.1)
PATCH-302283Update for Mozilla Firefox ESR (38.2)
PATCH-302284Update for Mozilla Firefox ESR (38.2.1)
PATCH-302285Update for Mozilla Firefox ESR (38.3.0)
PATCH-302286Update for Mozilla Firefox ESR (38.4.0)
PATCH-302287Update for Mozilla Firefox ESR (38.5.0)
PATCH-302288Update for Mozilla Firefox ESR (38.5.1)
PATCH-302289Update for Mozilla Firefox ESR (38.5.2)
PATCH-302290Update for Mozilla Firefox ESR (38.6.0)
PATCH-302291Update for Mozilla Firefox ESR (38.6.1)
PATCH-302292Update for Mozilla Firefox ESR (38.7.0)
PATCH-343015Mozilla Firefox (132.0.2)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611807Mozilla Thunderbird For Mac (142.0)
PATCH-611807Mozilla Thunderbird For Mac (142.0)
PATCH-612783Mozilla Firefox For Mac (145.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234