CVE-2014-1496
published 2014-03-19CVE-2014-1496: Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
0.38%
30.1th percentile
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < 28.0 | 28.0 |
| mozilla | firefox | >= 24.0 < 24.4 | 24.4 |
| mozilla | seamonkey | < 2.25 | 2.25 |
| mozilla | thunderbird | < 24.4 | 24.4 |
| suse | suse_linux_enterprise_desktop | — | — |
| suse | suse_linux_enterprise_server | — | — |
| suse | suse_linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rg2h-rx22-64cp: Mozilla Firefox before 28
ghsa_unreviewed·2022-05-13
CVE-2014-1496 [MEDIUM] CWE-269 GHSA-rg2h-rx22-64cp: Mozilla Firefox before 28
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
Red Hat
Mozilla: Files extracted during updates are not always read only (MFSA 2014-16)
vendor_redhat·2014-03-18·CVSS 5.5
CVE-2014-1496 [MEDIUM] Mozilla: Files extracted during updates are not always read only (MFSA 2014-16)
Mozilla: Files extracted during updates are not always read only (MFSA 2014-16)
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
Statement: Not vulnerable. This issue does not affect the version of firefox and thunderbird package as shipped with Red Hat Enterprise Linux 5 and 6 because these packages are not updated via online updates from upstream sources.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00016.htmlhttp://www.mozilla.org/security/announce/2014/mfsa2014-16.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=925747https://security.gentoo.org/glsa/201504-01http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00016.htmlhttp://www.mozilla.org/security/announce/2014/mfsa2014-16.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=925747https://security.gentoo.org/glsa/201504-01
2014-03-19
Published