CVE-2014-1554
published 2014-09-03CVE-2014-1554: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0 allow remote attackers to cause a denial of service (memory…
PriorityP339critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.81%
92.4th percentile
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 31.1.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 32.0+build1-0ubuntu0.14.04.1 | 32.0+build1-0ubuntu0.14.04.1 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h6cc-vr2r-vfmx: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32
ghsa_unreviewed·2022-05-17
CVE-2014-1554 [HIGH] CWE-119 GHSA-h6cc-vr2r-vfmx: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
OSV
firefox vulnerabilities
osv·2014-09-02·CVSS 10.0
CVE-2014-1553 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Jan de Mooij, Christian Holler, Karl Tomlinson, Randell Jesup, Gary Kwong,
Jesse Ruderman, JW Wang and David Weir discovered multiple memory safety
issues in Firefox. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2014-1553,
CVE-2014-1554, CVE-2014-1562)
Abhishek Arya discovered a use-after-free during DOM interactions with
SVG. If a user were tricked in to opening a specially crafted page, an
attacker could potentially exploit this to cause a denial of service via
application crash or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2014-1563
OSV
CVE-2014-1554: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32
osv·2014-09-02·CVSS 10.0
CVE-2014-1554 [CRITICAL] CVE-2014-1554: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Red Hat
Mozilla: Miscellaneous memory safety hazards (rv:32.0 / rv:31.1) (MFSA 2014-67)
vendor_redhat·2014-09-03·CVSS 10.0
CVE-2014-1554 [CRITICAL] Mozilla: Miscellaneous memory safety hazards (rv:32.0 / rv:31.1) (MFSA 2014-67)
Mozilla: Miscellaneous memory safety hazards (rv:32.0 / rv:31.1) (MFSA 2014-67)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 10.0
CVE-2014-1553 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Jan de Mooij, Christian Holler, Karl Tomlinson, Randell Jesup, Gary Kwong,
Jesse Ruderman, JW Wang and David Weir discovered multiple memory safety
issues in Firefox. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2014-1553,
CVE-2014-1554, CVE-2014-1562)
Abhishek Arya discovered a use-after-free during DOM interactions with
SVG. If a user were tricked in to opening a specially crafted page, an
attacker could potentially exploit this to cause a denial of service
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-updates/2014-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00002.htmlhttp://secunia.com/advisories/62022http://secunia.com/advisories/62023http://www.mozilla.org/security/announce/2014/mfsa2014-67.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/69526http://www.securitytracker.com/id/1030793http://www.securitytracker.com/id/1030794https://bugzilla.mozilla.org/show_bug.cgi?id=1004480https://bugzilla.mozilla.org/show_bug.cgi?id=1016519https://bugzilla.mozilla.org/show_bug.cgi?id=990247https://bugzilla.mozilla.org/show_bug.cgi?id=995704https://security.gentoo.org/glsa/201504-01http://lists.opensuse.org/opensuse-updates/2014-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00002.htmlhttp://secunia.com/advisories/62022http://secunia.com/advisories/62023http://www.mozilla.org/security/announce/2014/mfsa2014-67.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/69526http://www.securitytracker.com/id/1030793http://www.securitytracker.com/id/1030794https://bugzilla.mozilla.org/show_bug.cgi?id=1004480https://bugzilla.mozilla.org/show_bug.cgi?id=1016519https://bugzilla.mozilla.org/show_bug.cgi?id=990247https://bugzilla.mozilla.org/show_bug.cgi?id=995704https://security.gentoo.org/glsa/201504-01
2014-09-03
Published