{"api_version":"1","generated_at":"2026-07-23T10:41:37+00:00","cve":"CVE-2015-4497","urls":{"html":"https://cve.report/CVE-2015-4497","api":"https://cve.report/api/cve/CVE-2015-4497.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-4497","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-4497"},"summary":{"title":"CVE-2015-4497","description":"Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.","state":"PUBLISHED","assigner":"mozilla","published_at":"2015-08-29 19:59:00","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/76502","name":"http://www.securityfocus.com/bid/76502","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mozilla Firefox CVE-2015-4497 Use After Free Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1175278","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1175278","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Access Denied","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2015/dsa-3345","name":"http://www.debian.org/security/2015/dsa-3345","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-3345-1 iceweasel","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-updates/2015-09/msg00000.html","name":"http://lists.opensuse.org/opensuse-updates/2015-09/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"openSUSE-SU-2015:1492-1: moderate: Security update for MozillaFirefox","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2015/mfsa2015-94.html","name":"http://www.mozilla.org/security/announce/2015/mfsa2015-94.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Use-after-free when resizing canvas element during restyling — Mozilla","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-2723-1","name":"http://www.ubuntu.com/usn/USN-2723-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-2723-1: Firefox vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1033397","name":"http://www.securitytracker.com/id/1033397","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mozilla Firefox Use-After-Free in nsIPresShell Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-406","name":"http://www.zerodayinitiative.com/advisories/ZDI-15-406","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00013.html","name":"http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00013.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE-SU-2015:1504-1: important: Security update for","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html","name":"http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE-SU-2015:2081-1: important: Security update for","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1164766","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1164766","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Access Denied","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-1693.html","name":"http://rhn.redhat.com/errata/RHSA-2015-1693.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html","name":"http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Solaris Bulletin - April 2016","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-4497","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-4497","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"4497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"38.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"38.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"38.0.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"38.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"38.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4497","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"40.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T06:18:11.935Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/2015/mfsa2015-94.html"},{"name":"DSA-3345","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2015/dsa-3345"},{"name":"SUSE-SU-2015:2081","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html"},{"name":"USN-2723-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2723-1"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-406"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1175278"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html"},{"name":"SUSE-SU-2015:1504","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00013.html"},{"name":"openSUSE-SU-2015:1492","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2015-09/msg00000.html"},{"name":"76502","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/76502"},{"name":"RHSA-2015:1693","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-1693.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1164766"},{"name":"1033397","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1033397"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-08-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-20T16:57:01.000Z","orgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","shortName":"mozilla"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/2015/mfsa2015-94.html"},{"name":"DSA-3345","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2015/dsa-3345"},{"name":"SUSE-SU-2015:2081","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html"},{"name":"USN-2723-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2723-1"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-406"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1175278"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html"},{"name":"SUSE-SU-2015:1504","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00013.html"},{"name":"openSUSE-SU-2015:1492","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-updates/2015-09/msg00000.html"},{"name":"76502","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/76502"},{"name":"RHSA-2015:1693","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-1693.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1164766"},{"name":"1033397","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1033397"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@mozilla.org","ID":"CVE-2015-4497","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.mozilla.org/security/announce/2015/mfsa2015-94.html","refsource":"CONFIRM","url":"http://www.mozilla.org/security/announce/2015/mfsa2015-94.html"},{"name":"DSA-3345","refsource":"DEBIAN","url":"http://www.debian.org/security/2015/dsa-3345"},{"name":"SUSE-SU-2015:2081","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html"},{"name":"USN-2723-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2723-1"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-15-406","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-15-406"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1175278","refsource":"CONFIRM","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1175278"},{"name":"http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html"},{"name":"SUSE-SU-2015:1504","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00013.html"},{"name":"openSUSE-SU-2015:1492","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-updates/2015-09/msg00000.html"},{"name":"76502","refsource":"BID","url":"http://www.securityfocus.com/bid/76502"},{"name":"RHSA-2015:1693","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2015-1693.html"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=1164766","refsource":"CONFIRM","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1164766"},{"name":"1033397","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1033397"}]}}}},"cveMetadata":{"assignerOrgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","assignerShortName":"mozilla","cveId":"CVE-2015-4497","datePublished":"2015-08-29T19:00:00.000Z","dateReserved":"2015-06-10T00:00:00.000Z","dateUpdated":"2024-08-06T06:18:11.935Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-08-29 19:59:00","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:*","matchCriteriaId":"35BF0AFB-26BA-4BEA-B6B8-11CF88E951DE"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:38.0.1:*:*:*:*:*:*:*","matchCriteriaId":"1F007CC6-9391-4E1C-A747-F3DE5E572FA5"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:38.0.5:*:*:*:*:*:*:*","matchCriteriaId":"45E9641F-430C-4B3A-BD63-EC13DBD3D1E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:38.1.0:*:*:*:*:*:*:*","matchCriteriaId":"5AADD23B-A8AF-4679-990D-C29A1D6EB5CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:38.2.0:*:*:*:*:*:*:*","matchCriteriaId":"6D098567-B55E-4EAC-8FAA-31FAFDD4058F"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:40.0.2:*:*:*:*:*:*:*","matchCriteriaId":"59E90F00-714E-4F60-877D-1ED031C81622"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"4497","Ordinal":"1","Title":"CVE-2015-4497","CVE":"CVE-2015-4497","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"4497","Ordinal":"1","NoteData":"Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.","Type":"Description","Title":"CVE-2015-4497"},{"CveYear":"2015","CveId":"4497","Ordinal":"2","NoteData":"2015-08-29","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"4497","Ordinal":"3","NoteData":"2016-12-20","Type":"Other","Title":"Modified"}]}}}