{"api_version":"1","generated_at":"2026-07-24T22:53:51+00:00","cve":"CVE-2015-0813","urls":{"html":"https://cve.report/CVE-2015-0813","api":"https://cve.report/api/cve/CVE-2015-0813.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-0813","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-0813"},"summary":{"title":"CVE-2015-0813","description":"Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file.","state":"PUBLISHED","assigner":"mozilla","published_at":"2015-04-01 10:59:12","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.1","severity":"","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:P","baseScore":5.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.mozilla.org/security/announce/2015/mfsa2015-31.html","name":"http://www.mozilla.org/security/announce/2015/mfsa2015-31.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Use-after-free when using the Fluendo MP3 GStreamer plugin — Mozilla","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1032000","name":"http://www.securitytracker.com/id/1032000","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mozilla Thunderbird Flaws Let Remote Users Execute Arbitrary Code and Conduct Cross-Site Request Forgery Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html","name":"http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Solaris Third Party Bulletin - April 2015","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-2550-1","name":"http://www.ubuntu.com/usn/USN-2550-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-2550-1: Firefox vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00006.html","name":"http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00006.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE-SU-2015:0704-1: important: Security update for","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2015/dsa-3212","name":"http://www.debian.org/security/2015/dsa-3212","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-3212-1 icedove","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0766.html","name":"http://rhn.redhat.com/errata/RHSA-2015-0766.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1106596","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1106596","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Access Denied","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-2552-1","name":"http://www.ubuntu.com/usn/USN-2552-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-2552-1: Thunderbird vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html","name":"http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] openSUSE-SU-2015:0677-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/73463","name":"http://www.securityfocus.com/bid/73463","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mozilla Firefox/Thunderbird CVE-2015-0813 Use After Free Memory Corruption Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.debian.org/security/2015/dsa-3211","name":"http://www.debian.org/security/2015/dsa-3211","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-3211-1 iceweasel","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html","name":"http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] openSUSE-SU-2015:0892-1: important: Update to Firefo","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html","name":"http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] openSUSE-SU-2015:1266-1: important: Mozilla (Firefox","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1031996","name":"http://www.securitytracker.com/id/1031996","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mozilla Firefox Bugs Let Remote Users Execute Arbitrary Code, Bypass Security Restrictions, and Obtain Potentially Sensitive Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0771.html","name":"http://rhn.redhat.com/errata/RHSA-2015-0771.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201512-10","name":"https://security.gentoo.org/glsa/201512-10","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mozilla Products: Multiple vulnerabilities  (GLSA 201512-10) — Gentoo Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-0813","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-0813","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"813","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"813","vulnerable":"1","versionEndIncluding":"31.5.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"813","vulnerable":"1","versionEndIncluding":"36.0.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"813","vulnerable":"1","versionEndIncluding":"31.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"thunderbird","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T04:26:11.047Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"73463","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/73463"},{"name":"1031996","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1031996"},{"name":"openSUSE-SU-2015:0892","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html"},{"name":"GLSA-201512-10","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201512-10"},{"name":"DSA-3212","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2015/dsa-3212"},{"name":"SUSE-SU-2015:0704","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00006.html"},{"name":"USN-2552-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2552-1"},{"name":"RHSA-2015:0766","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0766.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/2015/mfsa2015-31.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html"},{"name":"openSUSE-SU-2015:1266","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html"},{"name":"USN-2550-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2550-1"},{"name":"1032000","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1032000"},{"name":"openSUSE-SU-2015:0677","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html"},{"name":"RHSA-2015:0771","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0771.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1106596"},{"name":"DSA-3211","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2015/dsa-3211"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-03-31T00:00:00.000Z","descriptions":[{"lang":"en","value":"Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-30T15:57:01.000Z","orgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","shortName":"mozilla"},"references":[{"name":"73463","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/73463"},{"name":"1031996","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1031996"},{"name":"openSUSE-SU-2015:0892","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html"},{"name":"GLSA-201512-10","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201512-10"},{"name":"DSA-3212","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2015/dsa-3212"},{"name":"SUSE-SU-2015:0704","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00006.html"},{"name":"USN-2552-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2552-1"},{"name":"RHSA-2015:0766","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0766.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/2015/mfsa2015-31.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html"},{"name":"openSUSE-SU-2015:1266","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html"},{"name":"USN-2550-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2550-1"},{"name":"1032000","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1032000"},{"name":"openSUSE-SU-2015:0677","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html"},{"name":"RHSA-2015:0771","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0771.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1106596"},{"name":"DSA-3211","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2015/dsa-3211"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@mozilla.org","ID":"CVE-2015-0813","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"73463","refsource":"BID","url":"http://www.securityfocus.com/bid/73463"},{"name":"1031996","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1031996"},{"name":"openSUSE-SU-2015:0892","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html"},{"name":"GLSA-201512-10","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201512-10"},{"name":"DSA-3212","refsource":"DEBIAN","url":"http://www.debian.org/security/2015/dsa-3212"},{"name":"SUSE-SU-2015:0704","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00006.html"},{"name":"USN-2552-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2552-1"},{"name":"RHSA-2015:0766","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2015-0766.html"},{"name":"http://www.mozilla.org/security/announce/2015/mfsa2015-31.html","refsource":"CONFIRM","url":"http://www.mozilla.org/security/announce/2015/mfsa2015-31.html"},{"name":"http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html"},{"name":"openSUSE-SU-2015:1266","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html"},{"name":"USN-2550-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2550-1"},{"name":"1032000","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1032000"},{"name":"openSUSE-SU-2015:0677","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html"},{"name":"RHSA-2015:0771","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2015-0771.html"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1106596","refsource":"CONFIRM","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1106596"},{"name":"DSA-3211","refsource":"DEBIAN","url":"http://www.debian.org/security/2015/dsa-3211"}]}}}},"cveMetadata":{"assignerOrgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","assignerShortName":"mozilla","cveId":"CVE-2015-0813","datePublished":"2015-04-01T10:00:00.000Z","dateReserved":"2015-01-07T00:00:00.000Z","dateUpdated":"2024-08-06T04:26:11.047Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-04-01 10:59:12","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:P","baseScore":5.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":4.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionEndIncluding":"31.5.3","matchCriteriaId":"C2177161-2E4F-4755-AB48-1D3142BA4208"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionEndIncluding":"36.0.4","matchCriteriaId":"4E600CCE-7BA3-410C-B089-9C7C27EE7D82"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*","versionEndIncluding":"31.5","matchCriteriaId":"FC3823E9-1BAA-4402-95E2-7AF5B793DEBE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"155AD4FB-E527-4103-BCEF-801B653DEA37"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"813","Ordinal":"1","Title":"CVE-2015-0813","CVE":"CVE-2015-0813","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"813","Ordinal":"1","NoteData":"Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file.","Type":"Description","Title":"CVE-2015-0813"},{"CveYear":"2015","CveId":"813","Ordinal":"2","NoteData":"2015-04-01","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"813","Ordinal":"3","NoteData":"2016-12-30","Type":"Other","Title":"Modified"}]}}}