CVE-2014-1543
published 2014-06-11CVE-2014-1543: Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API in Mozilla Firefox before 30.0 allow remote attackers to execute…
PriorityP347high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.76%
88.7th percentile
Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API in Mozilla Firefox before 30.0 allow remote attackers to execute arbitrary code by using non-contiguous axes with a (1) physical or (2) virtual Gamepad device.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 29.0.1 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
firefox: Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API (MFSA 2014-54)
vendor_redhat·2014-06-10·CVSS 7.5
CVE-2014-1543 [HIGH] CWE-122 firefox: Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API (MFSA 2014-54)
firefox: Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API (MFSA 2014-54)
Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API in Mozilla Firefox before 30.0 allow remote attackers to execute arbitrary code by using non-contiguous axes with a (1) physical or (2) virtual Gamepad device.
Statement: This issue does not affect the version of firefox as shipped with Red Hat Enterprise Linux 5 and 6
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-mj4m-r6rh-5xrx: Multiple heap-based buffer overflows in the navigator
ghsa_unreviewed·2022-05-14
CVE-2014-1543 [HIGH] CWE-119 GHSA-mj4m-r6rh-5xrx: Multiple heap-based buffer overflows in the navigator
Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API in Mozilla Firefox before 30.0 allow remote attackers to execute arbitrary code by using non-contiguous axes with a (1) physical or (2) virtual Gamepad device.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1543 firefox: Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API (MFSA 2014-54)
bugzilla·2014-06-12·CVSS 7.5
CVE-2014-1543 [HIGH] CVE-2014-1543 firefox: Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API (MFSA 2014-54)
CVE-2014-1543 firefox: Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API (MFSA 2014-54)
Security researcher Looben Yang reported a buffer overflow in Gamepad API when it is exercised with a gamepad device with non-contiguous axes. This can be either an actual physical device or by the installation of a virtual gamepad. This results in a potentially exploitable crash. The Gamepad API was introduced in Firefox 29 and this issue does not affect earlier versions.
External Reference:
http://www.mozilla.org/security/announce/2014/mfsa2014-54.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Looben Yang as the original reporter.
Statement:
This issue does not affect the version
Bugzilla
CVE-2014-1543 firefox: Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API (MFSA 2014-54) [fedora-all]
bugzilla·2014-06-12·CVSS 7.5
CVE-2014-1543 [HIGH] CVE-2014-1543 firefox: Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API (MFSA 2014-54) [fedora-all]
CVE-2014-1543 firefox: Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API (MFSA 2014-54) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bo
http://lists.opensuse.org/opensuse-updates/2014-06/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2014-07/msg00001.htmlhttp://secunia.com/advisories/59171http://secunia.com/advisories/59387http://secunia.com/advisories/59486http://secunia.com/advisories/59866http://www.mozilla.org/security/announce/2014/mfsa2014-54.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/67969http://www.securitytracker.com/id/1030388https://bugzilla.mozilla.org/show_bug.cgi?id=1011859https://security.gentoo.org/glsa/201504-01http://lists.opensuse.org/opensuse-updates/2014-06/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2014-07/msg00001.htmlhttp://secunia.com/advisories/59171http://secunia.com/advisories/59387http://secunia.com/advisories/59486http://secunia.com/advisories/59866http://www.mozilla.org/security/announce/2014/mfsa2014-54.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/67969http://www.securitytracker.com/id/1030388https://bugzilla.mozilla.org/show_bug.cgi?id=1011859https://security.gentoo.org/glsa/201504-01
2014-06-11
Published