CVE-2014-1567Use After Free in Mozilla Firefox

CWE-416Use After Free9 documents6 sources
Severity
9.3CRITICALNVD
OSV10.0
EPSS
2.6%
top 14.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 3
Latest updateMay 17

Description

Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows remote attackers to execute arbitrary code via text that is improperly handled during the interaction between directionality resolution and layout.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages5 packages

Ubuntumozilla/firefox< 32.0+build1-0ubuntu0.14.04.1
NVDmozilla/firefox31.1.0+7
NVDmozilla/firefox_esr6 versions+5
Ubuntumozilla/thunderbird< 1:31.1.1+build1-0ubuntu0.14.04.1
NVDmozilla/thunderbird11 versions+10

🔴Vulnerability Details

4
GHSA
GHSA-f94r-vch9-6352: Use-after-free vulnerability in DirectionalityUtils2022-05-17
OSV
thunderbird vulnerabilities2014-09-11
OSV
firefox vulnerabilities2014-09-02
OSV
CVE-2014-1567: Use-after-free vulnerability in DirectionalityUtils2014-09-02

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2014-09-11
Red Hat
Mozilla: Use-after-free setting text directionality (MFSA 2014-72)2014-09-03
Ubuntu
Firefox vulnerabilities2014-09-02

💬Community

1
Bugzilla
CVE-2014-1567 Mozilla: Use-after-free setting text directionality (MFSA 2014-72)2014-09-01