CVE-2014-1540
Ubuntu Security Notice USN-2243-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Use-after-free vulnerability in the nsEventListenerManager::CompileEventHandlerInternal function in the Event Listener Manager in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted web content.
Vulnerabilidad de uso después de liberación en la función nsEventListenerManager::CompileEventHandlerInternal en Event Listener Manager en Mozilla Firefox anterior a 30.0 permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria dinámica) a través de contenido web manipulado.
Gary Kwong, Christoph Diehl, Christian Holler, Hannes Verschore, Jan de Mooij, Ryan VanderMeulen, Jeff Walden, Kyle Huey, Jesse Ruderman, Gregor Wagner, Benoit Jacob and Karl Tomlinson discovered multiple memory safety issues in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-01-16 CVE Reserved
- 2014-06-11 CVE Published
- 2024-08-06 CVE Updated
- 2024-12-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/59052 | Third Party Advisory | |
http://secunia.com/advisories/59171 | Third Party Advisory | |
http://secunia.com/advisories/59387 | Third Party Advisory | |
http://secunia.com/advisories/59486 | Third Party Advisory | |
http://secunia.com/advisories/59866 | Third Party Advisory | |
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html | X_refsource_confirm |
|
http://www.securityfocus.com/bid/67978 | Vdb Entry | |
http://www.securitytracker.com/id/1030388 | Vdb Entry | |
https://bugzilla.mozilla.org/show_bug.cgi?id=978862 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-updates/2014-06/msg00040.html | 2017-12-28 | |
http://lists.opensuse.org/opensuse-updates/2014-07/msg00001.html | 2017-12-28 | |
http://www.mozilla.org/security/announce/2014/mfsa2014-51.html | 2017-12-28 | |
http://www.ubuntu.com/usn/USN-2243-1 | 2017-12-28 | |
https://security.gentoo.org/glsa/201504-01 | 2017-12-28 |