CVE-2015-2731

critical
Published 2015-07-06 · Modified 2026-05-06
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Use-after-free vulnerability in the CSPService::ShouldLoad function in the microtask implementation in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allows remote attackers to execute arbitrary code by leveraging client-side JavaScript that triggers removal of a DOM object on the basis of a Content Policy.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@mozilla.org — http://www.mozilla.org/security/announce/2015/mfsa2015-63.html

Application impact

VendorProductVersionsFixed
mozillafirefox{"endIncluding":"38.1.0"}
mozillathunderbird{"endIncluding":"38.0.1"}
mozillafirefox31.0
mozillafirefox31.1.0
mozillafirefox31.1.1
mozillafirefox31.3.0
mozillafirefox31.5.1
mozillafirefox31.5.2
mozillafirefox31.5.3
mozillafirefox38.0
mozillafirefox_esr31.1
mozillafirefox_esr31.2
mozillafirefox_esr31.3
mozillafirefox_esr31.4
mozillafirefox_esr31.5
mozillafirefox_esr31.6.0
mozillafirefox_esr31.7.0

References

Verify integrity in audit chain (admin only). AS-IS.