CVE-2015-2706: Mozilla Firefox
Medium severity, CVSS 6.8. EPSS: 2.6% chance of exploitation in the next 30 days.
Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted plugin that does not properly complete initialization.
Affected products
- Mozilla Firefox: up to and including 37.0.1
Published 2015-04-27. Last modified 2026-06-17.