CVE-2014-1544

CVSS v2.0 10 (High)
100% Progress
EPSS 10.63 % (95th)
10.63% Progress
Affected Products 4
Advisories 13

Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.

Weaknesses
CWE-NVD-Other
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2014-07-23 11:12:42
(10 years ago)
Updated Date
2017-01-07 02:59:38
(7 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 30.0 and prior versions cpe:2.3:a:mozilla:firefox <= 30.0
  Mozilla Firefox Esr 24.0 cpe:2.3:a:mozilla:firefox_esr:24.0
  Mozilla Firefox Esr 24.0.1 cpe:2.3:a:mozilla:firefox_esr:24.0.1
  Mozilla Firefox Esr 24.0.2 cpe:2.3:a:mozilla:firefox_esr:24.0.2
  Mozilla Firefox Esr 24.1.0 cpe:2.3:a:mozilla:firefox_esr:24.1.0
  Mozilla Firefox Esr 24.1.1 cpe:2.3:a:mozilla:firefox_esr:24.1.1
  Mozilla Firefox Esr 24.2 cpe:2.3:a:mozilla:firefox_esr:24.2
  Mozilla Firefox Esr 24.3 cpe:2.3:a:mozilla:firefox_esr:24.3
  Mozilla Firefox Esr 24.4 cpe:2.3:a:mozilla:firefox_esr:24.4
  Mozilla Firefox Esr 24.5 cpe:2.3:a:mozilla:firefox_esr:24.5
  Mozilla Firefox Esr 24.6 cpe:2.3:a:mozilla:firefox_esr:24.6
  Mozilla Network Security Services 3.2 cpe:2.3:a:mozilla:network_security_services:3.2
  Mozilla Network Security Services 3.2.1 cpe:2.3:a:mozilla:network_security_services:3.2.1
  Mozilla Network Security Services 3.3 cpe:2.3:a:mozilla:network_security_services:3.3
  Mozilla Network Security Services 3.3.1 cpe:2.3:a:mozilla:network_security_services:3.3.1
  Mozilla Network Security Services 3.3.2 cpe:2.3:a:mozilla:network_security_services:3.3.2
  Mozilla Network Security Services 3.4 cpe:2.3:a:mozilla:network_security_services:3.4
  Mozilla Network Security Services 3.4.1 cpe:2.3:a:mozilla:network_security_services:3.4.1
  Mozilla Network Security Services 3.4.2 cpe:2.3:a:mozilla:network_security_services:3.4.2
  Mozilla Network Security Services 3.5 cpe:2.3:a:mozilla:network_security_services:3.5
  Mozilla Network Security Services 3.6 cpe:2.3:a:mozilla:network_security_services:3.6
  Mozilla Network Security Services 3.6.1 cpe:2.3:a:mozilla:network_security_services:3.6.1
  Mozilla Network Security Services 3.7 cpe:2.3:a:mozilla:network_security_services:3.7
  Mozilla Network Security Services 3.7.1 cpe:2.3:a:mozilla:network_security_services:3.7.1
  Mozilla Network Security Services 3.7.2 cpe:2.3:a:mozilla:network_security_services:3.7.2
  Mozilla Network Security Services 3.7.3 cpe:2.3:a:mozilla:network_security_services:3.7.3
  Mozilla Network Security Services 3.7.5 cpe:2.3:a:mozilla:network_security_services:3.7.5
  Mozilla Network Security Services 3.7.7 cpe:2.3:a:mozilla:network_security_services:3.7.7
  Mozilla Network Security Services 3.8 cpe:2.3:a:mozilla:network_security_services:3.8
  Mozilla Network Security Services 3.9 cpe:2.3:a:mozilla:network_security_services:3.9
  Mozilla Network Security Services 3.11.2 cpe:2.3:a:mozilla:network_security_services:3.11.2
  Mozilla Network Security Services 3.11.3 cpe:2.3:a:mozilla:network_security_services:3.11.3
  Mozilla Network Security Services 3.11.4 cpe:2.3:a:mozilla:network_security_services:3.11.4
  Mozilla Network Security Services 3.11.5 cpe:2.3:a:mozilla:network_security_services:3.11.5
  Mozilla Network Security Services 3.12 cpe:2.3:a:mozilla:network_security_services:3.12
  Mozilla Network Security Services 3.12.1 cpe:2.3:a:mozilla:network_security_services:3.12.1
  Mozilla Network Security Services 3.12.2 cpe:2.3:a:mozilla:network_security_services:3.12.2
  Mozilla Network Security Services 3.12.3 cpe:2.3:a:mozilla:network_security_services:3.12.3
  Mozilla Network Security Services 3.12.3.1 cpe:2.3:a:mozilla:network_security_services:3.12.3.1
  Mozilla Network Security Services 3.12.3.2 cpe:2.3:a:mozilla:network_security_services:3.12.3.2
  Mozilla Network Security Services 3.12.4 cpe:2.3:a:mozilla:network_security_services:3.12.4
  Mozilla Network Security Services 3.12.5 cpe:2.3:a:mozilla:network_security_services:3.12.5
  Mozilla Network Security Services 3.12.6 cpe:2.3:a:mozilla:network_security_services:3.12.6
  Mozilla Network Security Services 3.12.7 cpe:2.3:a:mozilla:network_security_services:3.12.7
  Mozilla Network Security Services 3.12.8 cpe:2.3:a:mozilla:network_security_services:3.12.8
  Mozilla Network Security Services 3.12.9 cpe:2.3:a:mozilla:network_security_services:3.12.9
  Mozilla Network Security Services 3.12.10 cpe:2.3:a:mozilla:network_security_services:3.12.10
  Mozilla Network Security Services 3.12.11 cpe:2.3:a:mozilla:network_security_services:3.12.11
  Mozilla Network Security Services 3.14 cpe:2.3:a:mozilla:network_security_services:3.14
  Mozilla Network Security Services 3.14.1 cpe:2.3:a:mozilla:network_security_services:3.14.1
  Mozilla Network Security Services 3.14.2 cpe:2.3:a:mozilla:network_security_services:3.14.2
  Mozilla Network Security Services 3.14.3 cpe:2.3:a:mozilla:network_security_services:3.14.3
  Mozilla Network Security Services 3.14.4 cpe:2.3:a:mozilla:network_security_services:3.14.4
  Mozilla Network Security Services 3.14.5 cpe:2.3:a:mozilla:network_security_services:3.14.5
  Mozilla Network Security Services 3.15 cpe:2.3:a:mozilla:network_security_services:3.15
  Mozilla Network Security Services 3.15.1 cpe:2.3:a:mozilla:network_security_services:3.15.1
  Mozilla Network Security Services 3.15.2 cpe:2.3:a:mozilla:network_security_services:3.15.2
  Mozilla Network Security Services 3.15.3 cpe:2.3:a:mozilla:network_security_services:3.15.3
  Mozilla Network Security Services 3.15.3.1 cpe:2.3:a:mozilla:network_security_services:3.15.3.1
  Mozilla Network Security Services 3.15.4 cpe:2.3:a:mozilla:network_security_services:3.15.4
  Mozilla Network Security Services 3.15.5 cpe:2.3:a:mozilla:network_security_services:3.15.5
  Mozilla Network Security Services 3.16 cpe:2.3:a:mozilla:network_security_services:3.16
  Mozilla Thunderbird 24.6 and prior versions cpe:2.3:a:mozilla:thunderbird <= 24.6
  Mozilla Thunderbird 24.0 cpe:2.3:a:mozilla:thunderbird:24.0
  Mozilla Thunderbird 24.0.1 cpe:2.3:a:mozilla:thunderbird:24.0.1
  Mozilla Thunderbird 24.1 cpe:2.3:a:mozilla:thunderbird:24.1
  Mozilla Thunderbird 24.1.1 cpe:2.3:a:mozilla:thunderbird:24.1.1
  Mozilla Thunderbird 24.2 cpe:2.3:a:mozilla:thunderbird:24.2
  Mozilla Thunderbird 24.3 cpe:2.3:a:mozilla:thunderbird:24.3
  Mozilla Thunderbird 24.4 cpe:2.3:a:mozilla:thunderbird:24.4
  Mozilla Thunderbird 24.5 cpe:2.3:a:mozilla:thunderbird:24.5
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...