The asm.js implementation in Mozilla Firefox before 36.0.3, Firefox ESR 31.x before 31.5.2, and SeaMonkey before 2.33.1 does not properly determine the cases in which bounds checking may be safely skipped during JIT compilation and heap access, which allows remote attackers to read or write to unintended memory locations, and consequently execute arbitrary code, via crafted JavaScript.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade firefox | Dec 1, 2016 | Mar 23, 2015 |
| Freebsd | — | Upgrade firefox-esrUpgrade linux-firefoxUpgrade linux-seamonkeyUpgrade firefoxUpgrade libxulUpgrade seamonkey | Dec 10, 2025 | Mar 22, 2015 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade www-client/firefox.Upgrade dev-libs/nspr.Upgrade www-client/seamonkey-bin.Upgrade www-client/seamonkey.Upgrade mail-client/thunderbird.Upgrade mail-client/thunderbird-bin. | Oct 30, 2017 | Mar 23, 2015 |
| Mfsa2015 29 | — | Upgrade to Mozilla Firefox ESR version 31.5.2Upgrade to Mozilla Firefox version 36.0.3Upgrade to the latest version of Mozilla Firefox | Mar 23, 2015 | Mar 20, 2015 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.33.1 | Mar 23, 2015 | Mar 20, 2015 |
| Oracle Solaris | — | Upgrade web/browser/firefox/multi-user-desktop to version 31.6.0-0.175.2.11.0.3.0 on Solaris 11.2Upgrade consolidation/desktop/desktop-incorporation to version 0.5.11-0.175.3.0.0.28.0 on Solaris 11.3Upgrade web/browser/firefox to version 31.6.0-0.175.2.11.0.3.0 on Solaris 11.2Upgrade web/data/firefox-bookmarks to version 31.6.0-0.175.2.11.0.3.0 on Solaris 11.2 | May 29, 2017 | Mar 23, 2015 |
| Oracle_linux | — | Upgrade firefox | Oct 16, 2024 | Mar 24, 2015 |
| Suse | — | Upgrade MozillaFirefoxUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translationsUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-devel | Dec 18, 2015 | Mar 23, 2015 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Mar 24, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub