Lucene search

K
cve[email protected]CVE-2014-1540
HistoryJun 11, 2014 - 10:57 a.m.

CVE-2014-1540

2014-06-1110:57:17
web.nvd.nist.gov
39
mozilla
firefox
cve-2014-1540
use-after-free vulnerability
remote code execution
heap memory corruption
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

9.5

Confidence

High

EPSS

0.024

Percentile

89.9%

Use-after-free vulnerability in the nsEventListenerManager::CompileEventHandlerInternal function in the Event Listener Manager in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted web content.

Affected configurations

NVD
Node
mozillafirefoxRange29.0.1
VendorProductVersionCPE
mozillafirefoxcpe:/a:mozilla:firefox::::

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

9.5

Confidence

High

EPSS

0.024

Percentile

89.9%