CVE-2015-2713

medium
Published 2015-05-14 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a document containing crafted text in conjunction with a Cascading Style Sheets (CSS) token sequence containing properties related to vertical text.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@mozilla.org — http://www.mozilla.org/security/announce/2015/mfsa2015-51.html

OS impact

OSVersionStatusFixed in
suse suse12.0affected
suse suse13.1affected
suse suse13.2affected

Application impact

VendorProductVersionsFixed
suse novellsuse_linux_enterprise_software_development_kit12.0
mozilla mozillafirefox{"endIncluding":"37.0.2"}
mozilla mozillathunderbird{"endIncluding":"31.5"}
mozilla mozillafirefox31.0
mozilla mozillafirefox31.1.0
mozilla mozillafirefox31.1.1
mozilla mozillafirefox31.3.0
mozilla mozillafirefox31.5.1
mozilla mozillafirefox31.5.2
mozilla mozillafirefox31.5.3
mozilla mozillafirefox_esr31.1
mozilla mozillafirefox_esr31.2
mozilla mozillafirefox_esr31.3
mozilla mozillafirefox_esr31.4
mozilla mozillafirefox_esr31.5
mozilla mozillafirefox_esr31.6.0

References

Verify integrity in audit chain (admin only). AS-IS.