// For flags

CVE-2014-1478

 

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the MPostWriteBarrier class in js/src/jit/MIR.h and stack alignment in js/src/jit/AsmJS.cpp in OdinMonkey, and unknown other vectors.

Múltiples vulnerabilidades no especificadas en el motor de navegación en Mozilla Firefox anterior a 27.0 y SeaMonkey anterior a 2.24 permite a atacantes remotos causar una denegación de servicio (corrupción de memoria y caída de la aplicación) o posiblemente ejecutar un código arbitrario a través de vectores relacionados con la clase MPostWriteBarrier en js/src/jit/MIR.h y alineación de pila en js/src/jit/AsmJS.cpp en OdinMonkey y otros vectores desconocidos.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-01-16 CVE Reserved
  • 2014-02-06 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-08-24 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-787: Out-of-bounds Write
CAPEC
References (39)
URL Date SRC
URL Date SRC
URL Date SRC
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html 2024-02-14
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html 2024-02-14
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html 2024-02-14
http://www.mozilla.org/security/announce/2014/mfsa2014-01.html 2024-02-14
http://www.ubuntu.com/usn/USN-2102-1 2024-02-14
http://www.ubuntu.com/usn/USN-2102-2 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=867597 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=911707 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=911845 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=916635 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=922603 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=924348 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=925308 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=932162 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=938431 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=939472 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=942152 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=942940 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=944278 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=944321 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=944851 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=945585 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=946733 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=950452 2024-02-14
https://bugzilla.mozilla.org/show_bug.cgi?id=953373 2024-02-14
https://security.gentoo.org/glsa/201504-01 2024-02-14
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
< 27.0
Search vendor "Mozilla" for product "Firefox" and version " < 27.0"
-
Affected
Mozilla
Search vendor "Mozilla"
Seamonkey
Search vendor "Mozilla" for product "Seamonkey"
< 2.24
Search vendor "Mozilla" for product "Seamonkey" and version " < 2.24"
-
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
12.04
Search vendor "Canonical" for product "Ubuntu Linux" and version "12.04"
esm
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
12.10
Search vendor "Canonical" for product "Ubuntu Linux" and version "12.10"
-
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
13.10
Search vendor "Canonical" for product "Ubuntu Linux" and version "13.10"
-
Affected
Opensuse
Search vendor "Opensuse"
Opensuse
Search vendor "Opensuse" for product "Opensuse"
11.4
Search vendor "Opensuse" for product "Opensuse" and version "11.4"
-
Affected
Opensuse
Search vendor "Opensuse"
Opensuse
Search vendor "Opensuse" for product "Opensuse"
12.3
Search vendor "Opensuse" for product "Opensuse" and version "12.3"
-
Affected
Opensuse
Search vendor "Opensuse"
Opensuse
Search vendor "Opensuse" for product "Opensuse"
13.1
Search vendor "Opensuse" for product "Opensuse" and version "13.1"
-
Affected
Oracle
Search vendor "Oracle"
Solaris
Search vendor "Oracle" for product "Solaris"
11.3
Search vendor "Oracle" for product "Solaris" and version "11.3"
-
Affected