CVE-2015-4488
Summary
| CVE | CVE-2015-4488 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-08-16 01:59:00 UTC |
| Updated | 2018-10-30 16:27:00 UTC |
| Description | Use-after-free vulnerability in the StyleAnimationValue class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 allows remote attackers to have an unspecified impact by leveraging a StyleAnimationValue::operator self assignment. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 15.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 15.04 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox Esr | 38.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.0.1 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.0.5 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.1.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.0.1 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.0.5 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.1.0 | All | All | All |
| Operating System | Mozilla | Firefox Os | 2.1.0 | All | All | All |
| Operating System | Mozilla | Firefox Os | 2.1.0 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.1 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.2 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.1 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.2 | All | All | All |
| Operating System | Oracle | Solaris | 11.3 | All | All | All |
| Operating System | Oracle | Solaris | 11.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Solaris Bulletin - April 2016 | CONFIRM | www.oracle.com | Third Party Advisory |
| 1176270 – (CVE-2015-4488) StyleAnimationValue::operator= uses objects after delete on self-assignment | CONFIRM | bugzilla.mozilla.org | Issue Tracking |
| [security-announce] openSUSE-SU-2015:1390-1: important: Security update | SUSE | lists.opensuse.org | Third Party Advisory |
| Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Obtain Potentially Sensitive Information, Bypass Security Restrictions, and Conduct Cross-Site Scripting Attacks - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Mozilla Products: Multiple vulnerabilities (GLSA 201605-06) — Gentoo security | GENTOO | security.gentoo.org | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| Mozilla Thunderbird Multiple Flaws Let Remote Users Execute Arbitrary Code and Local Users Gain Elevated Privileges - SecurityTracker | SECTRACK | www.securitytracker.com | |
| USN-2702-2: Ubufox update | Ubuntu | UBUNTU | www.ubuntu.com | Third Party Advisory |
| USN-2712-1: Thunderbird vulnerabilities | Ubuntu | UBUNTU | www.ubuntu.com | |
| Vulnerabilities found through code inspection — Mozilla | CONFIRM | www.mozilla.org | Vendor Advisory |
| [security-announce] SUSE-SU-2015:1528-1: important: Security update for | SUSE | lists.opensuse.org | |
| openSUSE-SU-2015:1453-1: moderate: Security update for MozillaThunderbir | SUSE | lists.opensuse.org | |
| Debian -- Security Information -- DSA-3333-1 iceweasel | DEBIAN | www.debian.org | |
| USN-2702-1: Firefox vulnerabilities | Ubuntu | UBUNTU | www.ubuntu.com | Third Party Advisory |
| Debian -- Security Information -- DSA-3410-1 icedove | DEBIAN | www.debian.org | |
| USN-2702-3: Firefox regression | Ubuntu | UBUNTU | www.ubuntu.com | |
| [security-announce] SUSE-SU-2015:1449-1: important: Security update for | SUSE | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2015:1389-1: important: Security update | SUSE | lists.opensuse.org | Third Party Advisory |
| openSUSE-SU-2015:1454-1: moderate: Security update for MozillaThunderbir | SUSE | lists.opensuse.org | |
| [security-announce] SUSE-SU-2015:2081-1: important: Security update for | SUSE | lists.opensuse.org | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.