CVE-2015-2715: Mozilla Firefox

Medium severity, CVSS 6.8. EPSS: 2.2% chance of exploitation in the next 30 days.

Race condition in the nsThreadManager::RegisterCurrentThread function in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and heap memory corruption) by leveraging improper Media Decoder Thread creation at the time of a shutdown.

Affected products

  • Mozilla Firefox: up to and including 37.0.2
  • Opensuse Opensuse: version 13.1 only; version 13.2 only

Published 2015-05-14. Last modified 2026-06-17.