Lucene search

K
cveMozillaCVE-2014-1563
HistorySep 03, 2014 - 10:55 a.m.

CVE-2014-1563

2014-09-0310:55:06
CWE-416
mozilla
web.nvd.nist.gov
49
cve-2014-1563
use-after-free vulnerability
domsvglength
mozilla firefox
remote attackers
arbitrary code
denial of service
heap memory corruption
svg animation
dom interaction

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

9.5

Confidence

High

EPSS

0.632

Percentile

97.9%

Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG animation with DOM interaction that triggers incorrect cycle collection.

Affected configurations

Nvd
Node
opensuseevergreenMatch11.4
OR
opensuseopensuseMatch12.3
OR
opensuseopensuseMatch13.1
Node
oraclesolarisMatch11.3
Node
mozillafirefoxRange31.1.0
OR
mozillafirefoxMatch30.0
OR
mozillafirefoxMatch31.0
OR
mozillafirefox_esrMatch31.0
OR
mozillathunderbirdMatch31.0
VendorProductVersionCPE
opensuseevergreen11.4cpe:2.3:o:opensuse:evergreen:11.4:*:*:*:*:*:*:*
opensuseopensuse12.3cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
opensuseopensuse13.1cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
oraclesolaris11.3cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillafirefox30.0cpe:2.3:a:mozilla:firefox:30.0:*:*:*:*:*:*:*
mozillafirefox31.0cpe:2.3:a:mozilla:firefox:31.0:*:*:*:*:*:*:*
mozillafirefox_esr31.0cpe:2.3:a:mozilla:firefox_esr:31.0:*:*:*:*:*:*:*
mozillathunderbird31.0cpe:2.3:a:mozilla:thunderbird:31.0:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

9.5

Confidence

High

EPSS

0.632

Percentile

97.9%