CVE-2015-4503
Description
The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open method call and send method calls, which allows remote TCP servers to obtain sensitive information from process memory by reading packet data, as demonstrated by availability of this API in a Firefox OS application.
Risk Information
Base Score
7.5
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.575
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Update for SeaMonkey (2.38) | Windows |
| Update for Mozilla Firefox (41.0) | Windows |
| Update for Mozilla Firefox (41.0.1) | Windows |
| Update for Mozilla Firefox (41.0.2) | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 40.0.3 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 40.0.3 | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-301495 | Update for SeaMonkey (2.38) |
| PATCH-302184 | Update for Mozilla Firefox (41.0) |
| PATCH-302185 | Update for Mozilla Firefox (41.0.1) |
| PATCH-302186 | Update for Mozilla Firefox (41.0.2) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234