Lucene search

K
cveMozillaCVE-2014-8634
HistoryJan 14, 2015 - 11:59 a.m.

CVE-2014-8634

2015-01-1411:59:03
mozilla
web.nvd.nist.gov
55
cve
2014
8634
mozilla
firefox
esr
thunderbird
seamonkey
denial of service
memory corruption
application crash
remote attackers
arbitrary code
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

10

Confidence

High

EPSS

0.058

Percentile

93.4%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

Affected configurations

Nvd
Node
mozillafirefox_esrMatch31.0
OR
mozillafirefox_esrMatch31.1.0
OR
mozillafirefox_esrMatch31.1.1
OR
mozillafirefox_esrMatch31.2
OR
mozillafirefox_esrMatch31.3.0
Node
mozillafirefoxRange34.0.5
Node
mozillaseamonkeyRange2.31
Node
mozillathunderbirdRange31.3.0
VendorProductVersionCPE
mozillafirefox_esr31.0cpe:2.3:a:mozilla:firefox_esr:31.0:*:*:*:*:*:*:*
mozillafirefox_esr31.1.0cpe:2.3:a:mozilla:firefox_esr:31.1.0:*:*:*:*:*:*:*
mozillafirefox_esr31.1.1cpe:2.3:a:mozilla:firefox_esr:31.1.1:*:*:*:*:*:*:*
mozillafirefox_esr31.2cpe:2.3:a:mozilla:firefox_esr:31.2:*:*:*:*:*:*:*
mozillafirefox_esr31.3.0cpe:2.3:a:mozilla:firefox_esr:31.3.0:*:*:*:*:*:*:*
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

References

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

10

Confidence

High

EPSS

0.058

Percentile

93.4%