CVE-2015-0831: Canonical Ubuntu Linux
Medium severity, CVSS 6.8. EPSS: 4.2% chance of exploitation in the next 30 days.
Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 14.10 only
- Mozilla Firefox: up to and including 35.0.1; version 0.1 only; version 0.2 only; version 0.3 only; version 0.4 only; version 0.5 only; …
- Mozilla Firefox ESR: version 31.1 only; version 31.2 only; version 31.3 only; version 31.4 only; version 31.5 only
- Mozilla Thunderbird: up to and including 31.4; version 31.0 only; version 31.1.2 only; version 31.2 only; version 31.3 only
- Red Hat Enterprise Linux: version 5 only; version 6.0 only
Published 2015-02-25. Last modified 2026-06-17.