Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36.0, might allow remote attackers to trigger problematic Developer Console information or possibly have unspecified other impact by leveraging incorrect macro expansion, related to the ots::ots_gasp_parse function.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefoxUpgrade seamonkeyUpgrade linux-seamonkeyUpgrade linux-firefoxUpgrade firefox-esrUpgrade thunderbirdUpgrade libxulUpgrade linux-thunderbird | Dec 10, 2025 | Feb 27, 2015 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade www-client/seamonkey.Upgrade www-client/firefox-bin.Upgrade www-client/firefox.Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey-bin.Upgrade dev-libs/nspr. | Oct 30, 2017 | Feb 25, 2015 |
| Mfsa2015 23 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 36.0 | Feb 26, 2015 | Feb 25, 2015 |
| Oracle Solaris | — | Upgrade runtime/tcl-8/tcl-sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade web/browser/firefox to version 38.4.0-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3/documentation to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | Feb 25, 2015 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-devel | Dec 18, 2015 | Feb 25, 2015 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Feb 25, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub