Lucene search

K
cveMozillaCVE-2014-1594
HistoryDec 11, 2014 - 11:59 a.m.

CVE-2014-1594

2014-12-1111:59:08
CWE-20
mozilla
web.nvd.nist.gov
51
cve
mozilla firefox
firefox esr
thunderbird
seamonkey
remote code execution
incorrect cast
security vulnerability

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

5

Confidence

High

EPSS

0.057

Percentile

93.4%

Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 might allow remote attackers to execute arbitrary code by leveraging an incorrect cast from the BasicThebesLayer data type to the BasicContainerLayer data type.

Affected configurations

Nvd
Node
mozillafirefoxRange33.0
OR
mozillafirefox_esrRange31.2
OR
mozillaseamonkeyRange2.30
OR
mozillathunderbirdRange31.2
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillafirefox_esr*cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

5

Confidence

High

EPSS

0.057

Percentile

93.4%