CVE-2014-1555 — Use After Free in Mozilla Firefox
Severity
9.3CRITICALNVD
OSV10.0
EPSS
3.4%
top 12.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 23
Latest updateMay 17
Description
Use-after-free vulnerability in the nsDocLoader::OnProgress function in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allows remote attackers to execute arbitrary code via vectors that trigger a FireOnStateChange event.
CVSS vector
AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0
Affected Packages5 packages
🔴Vulnerability Details
4📋Vendor Advisories
3💬Community
1Bugzilla
▶