Lucene search

K
cveMozillaCVE-2014-1555
HistoryJul 23, 2014 - 11:12 a.m.

CVE-2014-1555

2014-07-2311:12:43
mozilla
web.nvd.nist.gov
65
cve-2014-1555
use-after-free
mozilla firefox
remote code execution
nvd
vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

9.5

Confidence

High

EPSS

0.069

Percentile

94.0%

Use-after-free vulnerability in the nsDocLoader::OnProgress function in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allows remote attackers to execute arbitrary code via vectors that trigger a FireOnStateChange event.

Affected configurations

Nvd
Node
mozillafirefoxRange30.0
OR
mozillafirefox_esrMatch24.0
OR
mozillafirefox_esrMatch24.0.1
OR
mozillafirefox_esrMatch24.0.2
OR
mozillafirefox_esrMatch24.1.0
OR
mozillafirefox_esrMatch24.1.1
OR
mozillafirefox_esrMatch24.2
OR
mozillafirefox_esrMatch24.3
OR
mozillafirefox_esrMatch24.4
OR
mozillafirefox_esrMatch24.5
OR
mozillafirefox_esrMatch24.6
OR
mozillathunderbirdRange24.6
OR
mozillathunderbirdMatch24.0
OR
mozillathunderbirdMatch24.0.1
OR
mozillathunderbirdMatch24.1
OR
mozillathunderbirdMatch24.1.1
OR
mozillathunderbirdMatch24.2
OR
mozillathunderbirdMatch24.3
OR
mozillathunderbirdMatch24.4
OR
mozillathunderbirdMatch24.5
VendorProductVersionCPE
mozillathunderbird24.3cpe:/a:mozilla:thunderbird:24.3:::
mozillathunderbird24.5cpe:/a:mozilla:thunderbird:24.5:::
mozillafirefox_esr24.0.1cpe:/a:mozilla:firefox_esr:24.0.1:::
mozillafirefox_esr24.3cpe:/a:mozilla:firefox_esr:24.3:::
mozillafirefox_esr24.5cpe:/a:mozilla:firefox_esr:24.5:::
mozillathunderbird24.4cpe:/a:mozilla:thunderbird:24.4:::
mozillathunderbird24.1cpe:/a:mozilla:thunderbird:24.1:::
mozillathunderbird24.2cpe:/a:mozilla:thunderbird:24.2:::
mozillathunderbird24.1.1cpe:/a:mozilla:thunderbird:24.1.1:::
mozillathunderbird24.0cpe:/a:mozilla:thunderbird:24.0:::
Rows per page:
1-10 of 201

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

9.5

Confidence

High

EPSS

0.069

Percentile

94.0%