CVE-2014-1592

CWE-416Use After Free8 documents7 sources
Severity
6.8MEDIUM
EPSS
1.8%
top 17.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 17

Description

Use-after-free vulnerability in the nsHtml5TreeOperation function in xul.dll in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to execute arbitrary code by adding a second root element to an HTML5 document during parsing.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages5 packages

NVDmozilla/firefox31.2+1
Ubuntufirefox< 34.0+build2-0ubuntu0.14.04.1
Ubuntuthunderbird< 1:31.3.0+build1-0ubuntu0.14.04.1

🔴Vulnerability Details

3
GHSA
GHSA-w8p8-5h8h-72gq: Use-after-free vulnerability in the nsHtml5TreeOperation function in xul2022-05-17
CVEList
CVE-2014-1592: Use-after-free vulnerability in the nsHtml5TreeOperation function in xul2014-12-11
OSV
CVE-2014-1592: Use-after-free vulnerability in the nsHtml5TreeOperation function in xul2014-12-02

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2014-12-03
Ubuntu
Firefox vulnerabilities2014-12-02
Red Hat
Mozilla: Use-after-free during HTML5 parsing (MFSA 2014-87)2014-12-02

💬Community

1
Bugzilla
CVE-2014-1592 Mozilla: Use-after-free during HTML5 parsing (MFSA 2014-87)2014-12-01