CVE-2014-1549

CVSS v2.0 9.3 (High)
93% Progress
EPSS 4.44 % (93th)
4.44% Progress
Affected Products 2
Advisories 4

The mozilla::dom::AudioBufferSourceNodeEngine::CopyFromInputBuffer function in Mozilla Firefox before 31.0 and Thunderbird before 31.0 does not properly allocate Web Audio buffer memory, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via crafted audio content that is improperly handled during playback buffering.

Weaknesses
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2014-07-23 11:12:42
(10 years ago)
Updated Date
2017-01-07 02:59:39
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 30.0 and prior versions cpe:2.3:a:mozilla:firefox <= 30.0
  Mozilla Thunderbird 24.7 and prior versions cpe:2.3:a:mozilla:thunderbird <= 24.7
  Mozilla Thunderbird 24.0 cpe:2.3:a:mozilla:thunderbird:24.0
  Mozilla Thunderbird 24.0.1 cpe:2.3:a:mozilla:thunderbird:24.0.1
  Mozilla Thunderbird 24.1 cpe:2.3:a:mozilla:thunderbird:24.1
  Mozilla Thunderbird 24.1.1 cpe:2.3:a:mozilla:thunderbird:24.1.1
  Mozilla Thunderbird 24.2 cpe:2.3:a:mozilla:thunderbird:24.2
  Mozilla Thunderbird 24.3 cpe:2.3:a:mozilla:thunderbird:24.3
  Mozilla Thunderbird 24.4 cpe:2.3:a:mozilla:thunderbird:24.4
  Mozilla Thunderbird 24.5 cpe:2.3:a:mozilla:thunderbird:24.5
  Mozilla Thunderbird 24.6 cpe:2.3:a:mozilla:thunderbird:24.6
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...