CVE-2015-2716: Mozilla Firefox
High severity, CVSS 7.5. EPSS: 7.2% chance of exploitation in the next 30 days.
Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.
Affected products
- Mozilla Firefox: up to and including 37.0.2; version 31.0 only; version 31.1.0 only; version 31.1.1 only; version 31.3.0 only; version 31.5.1 only; …
- Mozilla Firefox ESR: version 31.1 only; version 31.2 only; version 31.3 only; version 31.4 only; version 31.5 only; version 31.6.0 only
- Mozilla Thunderbird: up to and including 31.5
- Novell Suse Linux Enterprise Desktop: version 12.0 only
- Novell Suse Linux Enterprise Server: version 12.0 only
- Novell Suse Linux Enterprise Software Development Kit: version 12.0 only
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Oracle Solaris: version 11.3 only
Published 2015-05-14. Last modified 2026-06-17.