CVE-2014-1592
Severity
6.8MEDIUM
EPSS
1.8%
top 17.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateMay 17
Description
Use-after-free vulnerability in the nsHtml5TreeOperation function in xul.dll in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to execute arbitrary code by adding a second root element to an HTML5 document during parsing.
CVSS vector
AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4
Affected Packages5 packages
🔴Vulnerability Details
3GHSA▶
GHSA-w8p8-5h8h-72gq: Use-after-free vulnerability in the nsHtml5TreeOperation function in xul↗2022-05-17
CVEList
▶
OSV
▶