CVE-2015-0827: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 2.9% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the mozilla::gfx::CopyRect function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to obtain sensitive information from uninitialized process memory via a malformed SVG graphic.

Affected products

  • Mozilla Firefox: up to and including 35.0.1; version 0.1 only; version 0.2 only; version 0.3 only; version 0.4 only; version 0.5 only; …
  • Mozilla Firefox ESR: version 31.1 only; version 31.2 only; version 31.3 only; version 31.4 only; version 31.5 only
  • Mozilla Thunderbird: up to and including 31.4; version 31.0 only; version 31.1.2 only; version 31.2 only; version 31.3 only

Published 2015-02-25. Last modified 2026-06-17.