Security Advisory

CVE-2015-2706

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-04-24 23:00:00
Last updated 2024-08-06 05:24:38
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted plugin that does not properly complete initialization.