Your submission was sent successfully! Close

CVE-2015-4492

Published: 11 August 2015

Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 might allow remote attackers to execute arbitrary code via a SharedWorker object that makes recursive calls to the open method of an XMLHttpRequest object.

Priority

Medium

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
precise
Released (40.0+build4-0ubuntu0.12.04.1)
trusty Does not exist
(trusty was released [40.0+build4-0ubuntu0.14.04.1])
upstream
Released (40.0)
vivid
Released (40.0+build4-0ubuntu0.15.04.1)