CVE-2015-2740

critical
Published 2015-07-06 · Modified 2026-05-06
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote attackers to cause a denial of service or have unspecified other impact via unknown vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@mozilla.org — http://www.mozilla.org/security/announce/2015/mfsa2015-66.html

OS impact

OSVersionStatusFixed in
ubuntu ubuntu12.04affected
ubuntu ubuntu14.04affected
ubuntu ubuntu14.10affected
ubuntu ubuntu15.04affected
debian debian7.0affected
debian debian8.0affected
suse suse11affected
suse suse12.0affected

Application impact

VendorProductVersionsFixed
mozillathunderbird{"endIncluding":"38.0.1"}
mozillafirefox31.0
mozillafirefox31.1.0
mozillafirefox31.1.1
mozillafirefox31.3.0
mozillafirefox31.5.1
mozillafirefox31.5.2
mozillafirefox31.5.3
mozillafirefox38.0
mozillafirefox_esr31.1
mozillafirefox_esr31.2
mozillafirefox_esr31.3
mozillafirefox_esr31.4
mozillafirefox_esr31.5
mozillafirefox_esr31.6.0
mozillafirefox_esr31.7.0
novellsuse_linux_enterprise_software_development_kit12.0
mozillafirefox{"endIncluding":"38.1.0"}

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.