CVE-2014-1550
published 2014-07-23CVE-2014-1550: Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allows remote attackers to execute…
PriorityP341critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.90%
91.2th percentile
Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging incorrect Web Audio control-message ordering.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 30.0 | — |
| mozilla | firefox | >= 0 < 31.0+build1-0ubuntu0.14.04.1 | 31.0+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | <= 24.7 | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | >= 0 < 1:31.0+build1-0ubuntu0.14.04.1 | 1:31.0+build1-0ubuntu0.14.04.1 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xprg-g3m2-wcjv: Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31
ghsa_unreviewed·2022-05-17
CVE-2014-1550 [HIGH] GHSA-xprg-g3m2-wcjv: Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31
Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging incorrect Web Audio control-message ordering.
OSV
CVE-2014-1550: Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31
osv·2014-07-22·CVSS 10.0
CVE-2014-1550 [CRITICAL] CVE-2014-1550: Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31
Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging incorrect Web Audio control-message ordering.
OSV
firefox vulnerabilities
osv·2014-07-22·CVSS 10.0
[CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Christian Holler, David Keeler, Byron Campen, Gary Kwong, Jesse Ruderman,
Andrew McCreight, Alon Zakai, Bobby Holley, Jonathan Watt, Shu-yu Guo,
Steve Fink, Terrence Cole, Gijs Kruitbosch and Cătălin Badea discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-1547, CVE-2014-1548)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. An attacker could potentially exploit this to cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking Fi
OSV
thunderbird vulnerabilities
osv·2014-07-22·CVSS 10.0
CVE-2014-1547 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler, David Keeler and Byron Campen discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message with scripting enabled, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2014-1547)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. If a user had enabled scripting, an attacker could potentially
exploit this to cause a denial of service via application crash or execute
arbitrary code with the privileges of the user invoking Thunderbird.
(CVE-2014-1549)
Atte Kettunen discovered a use-after-free in WebAudio. If a user had
enabled
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2014-07-22·CVSS 10.0
CVE-2014-1547 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Christian Holler, David Keeler and Byron Campen discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message with scripting enabled, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2014-1547)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. If a user had enabled scripting, an attacker could potentially
exploit this to cause a denial of service via application crash or execute
arbitrary code with the privileges of the user invoking Thunderbird.
(CVE-2014-1549)
Atte Kett
Red Hat
Mozilla: Use-after-free in Web Audio due to incorrect control message ordering (MFSA 2014-58)
vendor_redhat·2014-07-22·CVSS 10.0
CVE-2014-1550 [CRITICAL] CWE-416 Mozilla: Use-after-free in Web Audio due to incorrect control message ordering (MFSA 2014-58)
Mozilla: Use-after-free in Web Audio due to incorrect control message ordering (MFSA 2014-58)
Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging incorrect Web Audio control-message ordering.
Statement: This issue does not affect the version of thunderbird as shipped with Red Hat Enterprise Linux 5 and 6, or the version of firefox as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterpri
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2014-07-22·CVSS 10.0
CVE-2014-1547 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Christian Holler, David Keeler, Byron Campen, Gary Kwong, Jesse Ruderman,
Andrew McCreight, Alon Zakai, Bobby Holley, Jonathan Watt, Shu-yu Guo,
Steve Fink, Terrence Cole, Gijs Kruitbosch and Cătălin Badea discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-1547, CVE-2014-1548)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. An attacker could potentially exploit this to cause
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/59760http://secunia.com/advisories/60628http://www.mozilla.org/security/announce/2014/mfsa2014-58.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securitytracker.com/id/1030619http://www.securitytracker.com/id/1030620https://bugzilla.mozilla.org/show_bug.cgi?id=1020411https://security.gentoo.org/glsa/201504-01http://secunia.com/advisories/59760http://secunia.com/advisories/60628http://www.mozilla.org/security/announce/2014/mfsa2014-58.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securitytracker.com/id/1030619http://www.securitytracker.com/id/1030620https://bugzilla.mozilla.org/show_bug.cgi?id=1020411https://security.gentoo.org/glsa/201504-01
2014-07-23
Published