Lucene search

K
mozillaMozilla FoundationMFSA2014-55
HistoryJun 10, 2014 - 12:00 a.m.

Out of bounds write in NSPR — Mozilla

2014-06-1000:00:00
Mozilla Foundation
www.mozilla.org
25

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.07

Percentile

94.0%

Security researcher Abhishek Arya (Inferno) of the Google Chrome Security Team reported an out of bounds write in the Netscape Portable Runtime (NSPR) leading to a potentially exploitable crash or code execution. This issue is fixed in NSPR version 4.10.6.

Affected configurations

Vulners
Node
mozillanetscape_portable_runtimeRange<4.10.6
VendorProductVersionCPE
mozillanetscape_portable_runtime*cpe:2.3:a:mozilla:netscape_portable_runtime:*:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.07

Percentile

94.0%