CVE-2015-5962: Mozilla Firefox OS

Medium severity, CVSS 5.0. EPSS: 1.1% chance of exploitation in the next 30 days.

Integer signedness error in the SharedBufferManagerParent::RecvAllocateGrallocBuffer function in the buffer-management implementation in the graphics layer in Mozilla Firefox OS before 2.2 might allow attackers to cause a denial of service (memory corruption) via a negative value of a size parameter.

Affected products

  • Mozilla Firefox OS: up to and including 2.1.0

Published 2015-08-08. Last modified 2026-06-17.