CVE-2015-7196

medium
Published 2015-11-05 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, when a Java plugin is enabled, allow remote attackers to cause a denial of service (incorrect garbage collection and application crash) or possibly execute arbitrary code via a crafted Java applet that deallocates an in-use JavaScript wrapper.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@mozilla.org — http://www.mozilla.org/security/announce/2015/mfsa2015-130.html

Application impact

VendorProductVersionsFixed
mozillafirefox{"endIncluding":"41.0.2"}
mozillafirefox38.0
mozillafirefox38.0.1
mozillafirefox38.0.5
mozillafirefox38.1.0
mozillafirefox38.1.1
mozillafirefox38.2.0
mozillafirefox38.2.1
mozillafirefox38.3.0

References

CWEs

CWE-17

Verify integrity in audit chain (admin only). AS-IS.