CVE-2015-2731: Mozilla Firefox

High severity, CVSS 10.0. EPSS: 5.8% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the CSPService::ShouldLoad function in the microtask implementation in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allows remote attackers to execute arbitrary code by leveraging client-side JavaScript that triggers removal of a DOM object on the basis of a Content Policy.

Affected products

  • Mozilla Firefox: up to and including 38.1.0; version 31.0 only; version 31.1.0 only; version 31.1.1 only; version 31.3.0 only; version 31.5.1 only; …
  • Mozilla Firefox ESR: version 31.1 only; version 31.2 only; version 31.3 only; version 31.4 only; version 31.5 only; version 31.6.0 only; …
  • Mozilla Thunderbird: up to and including 38.0.1
  • Oracle Solaris: version 11.3 only

Published 2015-07-06. Last modified 2026-06-17.