CVE-2015-4484: Canonical Ubuntu Linux
Medium severity, CVSS 5.0. EPSS: 4.3% chance of exploitation in the next 30 days.
The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of service (application crash) by leveraging the use of shared memory and accessing (1) an Atomics object or (2) a SharedArrayBuffer object.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only
- Mozilla Firefox: up to and including 39.0.3; version 38.0 only; version 38.0.1 only; version 38.0.5 only; version 38.1.0 only
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Oracle Solaris: version 11.3 only
Published 2015-08-16. Last modified 2026-06-17.