Back

MEDIUM

Mozilla: Double-free when using non-default memory allocators with a zero-length XHR (MFSA 2015-18)

Published Feb 25, 2015

Description

Double free vulnerability in the nsXMLHttpRequest::GetResponse function in Mozilla Firefox before 36.0, when a nonstandard memory allocator is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted JavaScript code that makes an XMLHttpRequest call with zero bytes of data.

Affected products

Remediation

Red Hat statement

This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.

Weaknesses (1)

References (15)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mozilla
Published Feb 25, 2015
Updated Aug 6, 2024
Reserved Jan 7, 2015

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Feb 24, 2015
Bugzilla 1195621

ENISA EUVD

Assigner mozilla
Published Feb 25, 2015
Updated Aug 6, 2024

GitHub

No data