CVE-2015-2722: Mozilla Firefox
High severity, CVSS 10.0. EPSS: 6.2% chance of exploitation in the next 30 days.
Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a shared worker.
Affected products
- Mozilla Firefox: version 31.0 only; version 31.1.0 only; version 31.1.1 only; version 31.3.0 only; version 31.5.1 only; version 31.5.2 only; …
- Mozilla Firefox ESR: version 31.1 only; version 31.2 only; version 31.3 only; version 31.4 only; version 31.5 only; version 31.6.0 only; …
- Novell Suse Linux Enterprise Desktop: version 12.0 only
- Novell Suse Linux Enterprise Server: version 11 only; version 12.0 only
- Novell Suse Linux Enterprise Software Development Kit: version 12.0 only
- Oracle Solaris: version 11.3 only
Published 2015-07-06. Last modified 2026-06-17.