CVE-2015-4507: Mozilla Firefox

Medium severity, CVSS 5.1. EPSS: 3.2% chance of exploitation in the next 30 days.

The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbitrary code via a crafted web site.

Affected products

  • Mozilla Firefox: up to and including 40.0.3

Published 2015-09-24. Last modified 2026-06-17.