Race condition in the nsThreadManager::RegisterCurrentThread function in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and heap memory corruption) by leveraging improper Media Decoder Thread creation at the time of a shutdown.
http://lists.opensuse.org/opensuse-updates/2015-05/msg00036.html
http://www.mozilla.org/security/announce/2015/mfsa2015-53.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.securityfocus.com/bid/74611
http://www.ubuntu.com/usn/USN-2602-1
OR
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* versions up to 37.0.2 (inclusive)
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
701255 | Mozilla Firefox ESR < 31.7 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
91379 | GLSA-201605-06 : Mozilla Products: Multiple vulnerabilities (Logjam) (SLOTH) | Nessus | Gentoo Local Security Checks | critical |
8865 | Mozilla Firefox < 38.0 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
83801 | openSUSE Security Update : MozillaFirefox (openSUSE-2015-375) | Nessus | SuSE Local Security Checks | critical |
83439 | Firefox < 38.0 Multiple Vulnerabilities | Nessus | Windows | critical |
83437 | Firefox < 38.0 Multiple Vulnerabilities (Mac OS X) | Nessus | MacOS X Local Security Checks | high |
83434 | Ubuntu 12.04 LTS / 14.04 LTS / 14.10 / 15.04 : firefox vulnerabilities (USN-2602-1) | Nessus | Ubuntu Local Security Checks | high |
83389 | FreeBSD : mozilla -- multiple vulnerabilities (d9b43004-f5fd-4807-b1d7-dbf66455b244) | Nessus | FreeBSD Local Security Checks | critical |