CVE-2014-1565 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Mozilla Firefox
Severity
5.0MEDIUMNVD
OSV10.0
EPSS
0.8%
top 25.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 3
Latest updateMay 17
Description
The mozilla::dom::AudioEventTimeline function in the Web Audio API implementation in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 does not properly create audio timelines, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via crafted API calls.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages4 packages
🔴Vulnerability Details
4📋Vendor Advisories
3💬Community
1Bugzilla
▶