CVE-2015-4510: Mozilla Firefox
Medium severity, CVSS 6.8. EPSS: 3% chance of exploitation in the next 30 days.
Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) by leveraging improper interaction between shared workers and the IndexedDB implementation.
Affected products
- Mozilla Firefox: up to and including 40.0.3
Published 2015-09-24. Last modified 2026-06-17.