CVE-2015-2740: Canonical Ubuntu Linux
High severity, CVSS 10.0. EPSS: 5.6% chance of exploitation in the next 30 days.
Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote attackers to cause a denial of service or have unspecified other impact via unknown vectors.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 14.10 only; version 15.04 only
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Mozilla Firefox: version 31.0 only; version 31.1.0 only; version 31.1.1 only; version 31.3.0 only; version 31.5.1 only; version 31.5.2 only; …
- Mozilla Firefox ESR: version 31.1 only; version 31.2 only; version 31.3 only; version 31.4 only; version 31.5 only; version 31.6.0 only; …
- Mozilla Thunderbird: up to and including 38.0.1
- Novell Suse Linux Enterprise Desktop: version 12.0 only
- Novell Suse Linux Enterprise Server: version 11 only; version 12.0 only
- Novell Suse Linux Enterprise Software Development Kit: version 12.0 only
- Oracle Solaris: version 11.3 only
Published 2015-07-06. Last modified 2026-06-17.