CVE-2014-1532

CVSS v3.1 9.8 (Critical)
98% Progress
CVSS v2.0 7.5 (High)
75% Progress
EPSS 2.11 % (89th)
2.11% Progress
Affected Products 16
Advisories 10

Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to host resolution.

Weaknesses
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2014-04-30 10:49:05
(10 years ago)
Updated Date
2020-08-06 17:57:46
(4 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 29.0 version cpe:2.3:a:mozilla:firefox < 29.0
  Mozilla Firefox Esr from 24.0 version and prior 24.5 version cpe:2.3:a:mozilla:firefox_esr >= 24.0 < 24.5
  Mozilla Seamonkey prior 2.26 version cpe:2.3:a:mozilla:seamonkey < 2.26
  Mozilla Thunderbird prior 24.5 version cpe:2.3:a:mozilla:thunderbird < 24.5

Configuration #2

    CPE23 From Up To
  Fedoraproject Fedora 19 cpe:2.3:o:fedoraproject:fedora:19
  Fedoraproject Fedora 20 cpe:2.3:o:fedoraproject:fedora:20

Configuration #3

    CPE23 From Up To
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm
  Canonical Ubuntu Linux 12.10 cpe:2.3:o:canonical:ubuntu_linux:12.10
  Canonical Ubuntu Linux 13.10 cpe:2.3:o:canonical:ubuntu_linux:13.10
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm

Configuration #4

    CPE23 From Up To
  Debian Linux 7.0 cpe:2.3:o:debian:debian_linux:7.0
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0

Configuration #5

    CPE23 From Up To
  Redhat Enterprise Linux Desktop 5.0 cpe:2.3:o:redhat:enterprise_linux_desktop:5.0
  Redhat Enterprise Linux Desktop 6.0 cpe:2.3:o:redhat:enterprise_linux_desktop:6.0
  Redhat Enterprise Linux Eus 6.5 cpe:2.3:o:redhat:enterprise_linux_eus:6.5
  Redhat Enterprise Linux Server 5.0 cpe:2.3:o:redhat:enterprise_linux_server:5.0
  Redhat Enterprise Linux Server 6.0 cpe:2.3:o:redhat:enterprise_linux_server:6.0
  Redhat Enterprise Linux Server Aus 6.5 cpe:2.3:o:redhat:enterprise_linux_server_aus:6.5
  Redhat Enterprise Linux Server Eus 6.5 cpe:2.3:o:redhat:enterprise_linux_server_eus:6.5
  Redhat Enterprise Linux Server Tus 6.5 cpe:2.3:o:redhat:enterprise_linux_server_tus:6.5
  Redhat Enterprise Linux Workstation 5.0 cpe:2.3:o:redhat:enterprise_linux_workstation:5.0
  Redhat Enterprise Linux Workstation 6.0 cpe:2.3:o:redhat:enterprise_linux_workstation:6.0

Configuration #6

    CPE23 From Up To
  Opensuse 11.4 cpe:2.3:o:opensuse:opensuse:11.4
  Opensuse 12.3 cpe:2.3:o:opensuse:opensuse:12.3
  Opensuse 13.1 cpe:2.3:o:opensuse:opensuse:13.1
  Suse Linux Enterprise Server 10 SP4 cpe:2.3:o:suse:suse_linux_enterprise_server:10:sp4:*:*:ltss
  Suse Linux Enterprise Server 11 SP1 cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp1:*:*:ltss
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...