CVE-2015-4510: Mozilla Firefox

Medium severity, CVSS 6.8. EPSS: 3% chance of exploitation in the next 30 days.

Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) by leveraging improper interaction between shared workers and the IndexedDB implementation.

Affected products

  • Mozilla Firefox: up to and including 40.0.3

Published 2015-09-24. Last modified 2026-06-17.