{"schema_version":"1.7.5","id":"CVE-2015-4506","published":"2015-09-24T04:59:09Z","modified":"2026-04-10T03:46:23.800383Z","related":["SUSE-SU-2015:1680-1","SUSE-SU-2015:1703-1","openSUSE-SU-2024:10071-1","openSUSE-SU-2024:10218-1","openSUSE-SU-2024:10230-1","openSUSE-SU-2024:14572-1"],"details":"Buffer overflow in the vp9_init_context_buffers function in libvpx, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3, allows remote attackers to execute arbitrary code via a crafted VP9 file.","references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2015-1834.html"},{"type":"ADVISORY","url":"http://www.debian.org/security/2015/dsa-3365"},{"type":"ADVISORY","url":"http://www.mozilla.org/security/announce/2015/mfsa2015-101.html"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-2743-1"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-2743-2"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-2743-3"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-2743-4"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-2754-1"},{"type":"REPORT","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1192226"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00000.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00003.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00004.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00005.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00007.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/76816"},{"type":"WEB","url":"http://www.securitytracker.com/id/1033640"}]}