// For flags

CVE-2014-1534

Ubuntu Security Notice USN-2243-1

Time Line
Published
2024-03-19
Updated
2024-03-19
Firt exploit
2024-03-19
Overview
Descriptions (3)
NVD, NVD, PS
CWE (1)
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC (-)
Risk
CVSS Score
9.8 Critical
SSVC
-
KEV
-
EPSS
7.0%
Affected Products (-)
Vendors (1)
mozilla
Products (1)
firefox
Versions (1)
<= 29.0.1
Intel Resources (3)
Advisories (3)
PacketStorm
Exploits (-)
-
Plugins (-)
-
References (33)
General (25)
secunia, oracle, securityfocus ...
Exploits & POcs (-)
Patches (-)
Advisories (8)
opensuse, mozilla, ubuntu, gentoo
Summary
Descriptions

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 30.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

Múltiples vulnerabilidades no especificadas en el motor del navegador en Mozilla Firefox anterior a 30.0 permiten a atacantes remotos causar una denegación de servicio (corrupción de memoria y caída de aplicación) o posiblemente ejecutar código arbitrario a través de vectores desconocidos.

Gary Kwong, Christoph Diehl, Christian Holler, Hannes Verschore, Jan de Mooij, Ryan VanderMeulen, Jeff Walden, Kyle Huey, Jesse Ruderman, Gregor Wagner, Benoit Jacob and Karl Tomlinson discovered multiple memory safety issues in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. Various other issues were also addressed.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-01-16 CVE Reserved
  • 2014-06-11 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-12-27 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Threat Intelligence Resources (3)
Security Advisory details:

Select an advisory to view details here.

Select an exploit to view details here.

References (33)
URL Tag Source
http://secunia.com/advisories/59052 Third Party Advisory
http://secunia.com/advisories/59171 Third Party Advisory
http://secunia.com/advisories/59229 Third Party Advisory
http://secunia.com/advisories/59377 Third Party Advisory
http://secunia.com/advisories/59387 Third Party Advisory
http://secunia.com/advisories/59425 Third Party Advisory
http://secunia.com/advisories/59486 Third Party Advisory
http://secunia.com/advisories/59866 Third Party Advisory
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html X_refsource_confirm
http://www.securityfocus.com/bid/67964 Vdb Entry
http://www.securitytracker.com/id/1030386 Vdb Entry
http://www.securitytracker.com/id/1030388 Vdb Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=1000598 X_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1000960 X_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1002340 X_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1005578 X_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1007223 X_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=969517 X_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=969549 X_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=973874 X_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=978652 X_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=990868 X_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=995816 X_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=995817 X_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=996536 X_refsource_confirm
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
<= 29.0.1
Search vendor "Mozilla" for product "Firefox" and version " <= 29.0.1"
-
Affected