CVE-2014-1559
published 2014-07-23CVE-2014-1559: Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.71%
75.0th percentile
Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use UTF-8 character encoding in a required context, a different vulnerability than CVE-2014-1558.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 30.0 | — |
| mozilla | firefox | >= 0 < 31.0+build1-0ubuntu0.14.04.1 | 31.0+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | <= 24.7 | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | >= 0 < 1:31.0+build1-0ubuntu0.14.04.1 | 1:31.0+build1-0ubuntu0.14.04.1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv10.0CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7x7g-6wq5-m98p: Mozilla Firefox before 31
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2014-1558 [MEDIUM] GHSA-7x7g-6wq5-m98p: Mozilla Firefox before 31
Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use UTF-8 character encoding in a required context, a different vulnerability than CVE-2014-1559.
GHSA
GHSA-rgg5-hwqp-j6m9: Mozilla Firefox before 31
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2014-1559 [MEDIUM] GHSA-rgg5-hwqp-j6m9: Mozilla Firefox before 31
Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use UTF-8 character encoding in a required context, a different vulnerability than CVE-2014-1558.
OSV
firefox vulnerabilities
osv·2014-07-22·CVSS 10.0
[CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Christian Holler, David Keeler, Byron Campen, Gary Kwong, Jesse Ruderman,
Andrew McCreight, Alon Zakai, Bobby Holley, Jonathan Watt, Shu-yu Guo,
Steve Fink, Terrence Cole, Gijs Kruitbosch and Cătălin Badea discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-1547, CVE-2014-1548)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. An attacker could potentially exploit this to cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking Fi
OSV
thunderbird vulnerabilities
osv·2014-07-22·CVSS 10.0
CVE-2014-1547 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler, David Keeler and Byron Campen discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message with scripting enabled, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2014-1547)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. If a user had enabled scripting, an attacker could potentially
exploit this to cause a denial of service via application crash or execute
arbitrary code with the privileges of the user invoking Thunderbird.
(CVE-2014-1549)
Atte Kettunen discovered a use-after-free in WebAudio. If a user had
enabled
OSV
CVE-2014-1559: Mozilla Firefox before 31
osv·2014-07-22·CVSS 4.3
CVE-2014-1559 [MEDIUM] CVE-2014-1559: Mozilla Firefox before 31
Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use UTF-8 character encoding in a required context, a different vulnerability than CVE-2014-1558.
OSV
CVE-2014-1558: Mozilla Firefox before 31
osv·2014-07-22·CVSS 4.3
CVE-2014-1558 [MEDIUM] CVE-2014-1558: Mozilla Firefox before 31
Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use UTF-8 character encoding in a required context, a different vulnerability than CVE-2014-1559.
Red Hat
Mozilla: Certificate parsing broken by non-standard character encoding (MFSA 2014-65)
vendor_redhat·2014-07-22·CVSS 4.3
CVE-2014-1559 [MEDIUM] Mozilla: Certificate parsing broken by non-standard character encoding (MFSA 2014-65)
Mozilla: Certificate parsing broken by non-standard character encoding (MFSA 2014-65)
Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use UTF-8 character encoding in a required context, a different vulnerability than CVE-2014-1558.
Statement: This issue does not affect the version of thunderbird as shipped with Red Hat Enterprise Linux 5 and 6, or the version of firefox as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linu
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2014-07-22·CVSS 10.0
CVE-2014-1547 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Christian Holler, David Keeler and Byron Campen discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message with scripting enabled, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2014-1547)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. If a user had enabled scripting, an attacker could potentially
exploit this to cause a denial of service via application crash or execute
arbitrary code with the privileges of the user invoking Thunderbird.
(CVE-2014-1549)
Atte Kett
Red Hat
Mozilla: Certificate parsing broken by non-standard character encoding (MFSA 2014-65)
vendor_redhat·2014-07-22·CVSS 4.3
CVE-2014-1558 [MEDIUM] Mozilla: Certificate parsing broken by non-standard character encoding (MFSA 2014-65)
Mozilla: Certificate parsing broken by non-standard character encoding (MFSA 2014-65)
Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use UTF-8 character encoding in a required context, a different vulnerability than CVE-2014-1559.
Statement: This issue does not affect the version of thunderbird as shipped with Red Hat Enterprise Linux 5 and 6, or the version of firefox as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linu
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2014-07-22·CVSS 10.0
CVE-2014-1547 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Christian Holler, David Keeler, Byron Campen, Gary Kwong, Jesse Ruderman,
Andrew McCreight, Alon Zakai, Bobby Holley, Jonathan Watt, Shu-yu Guo,
Steve Fink, Terrence Cole, Gijs Kruitbosch and Cătălin Badea discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-1547, CVE-2014-1548)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. An attacker could potentially exploit this to cause
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/60628http://www.mozilla.org/security/announce/2014/mfsa2014-65.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securitytracker.com/id/1030619http://www.securitytracker.com/id/1030620https://bugzilla.mozilla.org/show_bug.cgi?id=1026022https://security.gentoo.org/glsa/201504-01http://secunia.com/advisories/60628http://www.mozilla.org/security/announce/2014/mfsa2014-65.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securitytracker.com/id/1030619http://www.securitytracker.com/id/1030620https://bugzilla.mozilla.org/show_bug.cgi?id=1026022https://security.gentoo.org/glsa/201504-01
2014-07-23
Published