CVE-2015-2731: Mozilla Firefox
High severity, CVSS 10.0. EPSS: 5.8% chance of exploitation in the next 30 days.
Use-after-free vulnerability in the CSPService::ShouldLoad function in the microtask implementation in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allows remote attackers to execute arbitrary code by leveraging client-side JavaScript that triggers removal of a DOM object on the basis of a Content Policy.
Affected products
- Mozilla Firefox: up to and including 38.1.0; version 31.0 only; version 31.1.0 only; version 31.1.1 only; version 31.3.0 only; version 31.5.1 only; …
- Mozilla Firefox ESR: version 31.1 only; version 31.2 only; version 31.3 only; version 31.4 only; version 31.5 only; version 31.6.0 only; …
- Mozilla Thunderbird: up to and including 38.0.1
- Oracle Solaris: version 11.3 only
Published 2015-07-06. Last modified 2026-06-17.