CVE-2014-1544
published 2014-07-23CVE-2014-1544: Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before…
PriorityP347critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.11%
92.6th percentile
Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.
Affected
78 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.16.3-1 (bookworm) | nss 2:3.16.3-1 (bookworm) |
| mozilla | firefox | <= 30.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 31.0+build1-0ubuntu0.14.04.1 | 31.0+build1-0ubuntu0.14.04.1 |
| mozilla | firefox_esr | — | — |
| mozilla | firefox_esr | — | — |
| mozilla | firefox_esr | — | — |
| mozilla | firefox_esr | — | — |
| mozilla | firefox_esr | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NSS vulnerability
vendor_ubuntu·2014-09-09
CVE-2014-1544 NSS vulnerability
Title: NSS vulnerability
Summary: NSS could be made to crash or run programs as your login if it processed a
specially crafted certificate.
Tyson Smith and Jesse Schwartzentruber discovered that NSS contained a race
condition when performing certificate validation. An attacker could use
this issue to cause NSS to crash, resulting in a denial of service, or
possibly execute arbitrary code.
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Evolution and Chromium, to make all the necessary changes.
Red Hat
nss: Race-condition in certificate verification can lead to Remote code execution (MFSA 2014-63)
vendor_redhat·2014-07-22·CVSS 10.0
CVE-2014-1544 [CRITICAL] CWE-416 nss: Race-condition in certificate verification can lead to Remote code execution (MFSA 2014-63)
nss: Race-condition in certificate verification can lead to Remote code execution (MFSA 2014-63)
Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.
A race condition was found in the way NSS verified certain certificates. A remote attacker could use this flaw to crash an application using NSS or, possibly, execute arbitrary code with the privileges of the user running that application.
Package: nss (Red Hat Enterprise Linux Extended Update Support 5.6) - Affected
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2014-07-22·CVSS 10.0
CVE-2014-1547 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Christian Holler, David Keeler and Byron Campen discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message with scripting enabled, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2014-1547)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. If a user had enabled scripting, an attacker could potentially
exploit this to cause a denial of service via application crash or execute
arbitrary code with the privileges of the user invoking Thunderbird.
(CVE-2014-1549)
Atte Kett
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2014-07-22·CVSS 10.0
CVE-2014-1547 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Christian Holler, David Keeler, Byron Campen, Gary Kwong, Jesse Ruderman,
Andrew McCreight, Alon Zakai, Bobby Holley, Jonathan Watt, Shu-yu Guo,
Steve Fink, Terrence Cole, Gijs Kruitbosch and Cătălin Badea discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-1547, CVE-2014-1548)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. An attacker could potentially exploit this to cause
Debian
CVE-2014-1544: nss - Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3....
vendor_debian·2014·CVSS 10.0
CVE-2014-1544 [CRITICAL] CVE-2014-1544: nss - Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3....
Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.
Scope: local
bookworm: resolved (fixed in 2:3.16.3-1)
bullseye: resolved (fixed in 2:3.16.3-1)
forky: resolved (fixed in 2:3.16.3-1)
sid: resolved (fixed in 2:3.16.3-1)
trixie: resolved (fixed in 2:3.16.3-1)
GHSA
GHSA-pwp6-rmm8-g5j6: Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3
ghsa_unreviewed·2022-05-17
CVE-2014-1544 [HIGH] GHSA-pwp6-rmm8-g5j6: Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3
Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.
OSV
CVE-2014-1544: Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3
osv·2014-07-23·CVSS 10.0
CVE-2014-1544 [CRITICAL] CVE-2014-1544: Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3
Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.
OSV
firefox vulnerabilities
osv·2014-07-22·CVSS 10.0
[CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Christian Holler, David Keeler, Byron Campen, Gary Kwong, Jesse Ruderman,
Andrew McCreight, Alon Zakai, Bobby Holley, Jonathan Watt, Shu-yu Guo,
Steve Fink, Terrence Cole, Gijs Kruitbosch and Cătălin Badea discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-1547, CVE-2014-1548)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. An attacker could potentially exploit this to cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking Fi
OSV
thunderbird vulnerabilities
osv·2014-07-22·CVSS 10.0
CVE-2014-1547 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler, David Keeler and Byron Campen discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message with scripting enabled, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2014-1547)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. If a user had enabled scripting, an attacker could potentially
exploit this to cause a denial of service via application crash or execute
arbitrary code with the privileges of the user invoking Thunderbird.
(CVE-2014-1549)
Atte Kettunen discovered a use-after-free in WebAudio. If a user had
enabled
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/59591http://secunia.com/advisories/59719http://secunia.com/advisories/59760http://secunia.com/advisories/60083http://secunia.com/advisories/60486http://secunia.com/advisories/60621http://secunia.com/advisories/60628http://www.debian.org/security/2014/dsa-2986http://www.debian.org/security/2014/dsa-2996http://www.mozilla.org/security/announce/2014/mfsa2014-63.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/68816http://www.securitytracker.com/id/1030617https://bugzilla.mozilla.org/show_bug.cgi?id=963150https://security.gentoo.org/glsa/201504-01http://secunia.com/advisories/59591http://secunia.com/advisories/59719http://secunia.com/advisories/59760http://secunia.com/advisories/60083http://secunia.com/advisories/60486http://secunia.com/advisories/60621http://secunia.com/advisories/60628http://www.debian.org/security/2014/dsa-2986http://www.debian.org/security/2014/dsa-2996http://www.mozilla.org/security/announce/2014/mfsa2014-63.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/68816http://www.securitytracker.com/id/1030617https://bugzilla.mozilla.org/show_bug.cgi?id=963150https://security.gentoo.org/glsa/201504-01
2014-07-23
Published