Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted plugin that does not properly complete initialization.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefoxUpgrade linux-firefox | Dec 10, 2025 | Apr 21, 2015 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade mail-client/thunderbird.Upgrade www-client/firefox-bin.Upgrade www-client/firefox. | Oct 30, 2017 | Apr 27, 2015 |
| Mfsa2015 45 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 37.0.2 | Apr 23, 2015 | Apr 20, 2015 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.35.0 | Oct 22, 2015 | Apr 27, 2015 |
| Oracle Solaris | — | Upgrade runtime/tcl-8/tcl-sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade web/browser/firefox to version 38.4.0-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3/documentation to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | Apr 27, 2015 |
| Suse | — | Upgrade MozillaFirefoxUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-common | Dec 18, 2015 | Apr 24, 2015 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Apr 27, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub