cbcvebase.
CVE-2014-1525
published 2014-04-30

CVE-2014-1525: The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection for Text…

PriorityP341critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.41%
90.3th percentile
The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection for Text Track Manager variables, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and heap memory corruption) via a crafted VIDEO element in an HTML document.

Affected

10 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
fedoraprojectfedora
mozillafirefox< 29.029.0
mozillafirefox>= 0 < 29.0+build1-0ubuntu0.14.04.229.0+build1-0ubuntu0.14.04.2
mozillaseamonkey< 2.262.26
opensuseopensuse
opensuseopensuse

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.