CVE-2014-2458
published 2014-04-16CVE-2014-2458: Unspecified vulnerability in the Oracle Agile Product Lifecycle component in Oracle Supply Chain Products Suite 6.1.0.3 and 6.1.1.3 allows remote attackers to…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.04%
59.9th percentile
Unspecified vulnerability in the Oracle Agile Product Lifecycle component in Oracle Supply Chain Products Suite 6.1.0.3 and 6.1.1.3 allows remote attackers to affect integrity via unknown vectors related to Install.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | >= 0 < 35.0.1+build1-0ubuntu0.14.04.1 | 35.0.1+build1-0ubuntu0.14.04.1 |
| oracle | supply_chain_products_suite | — | — |
| oracle | supply_chain_products_suite | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Agile Product Lifecycle 6.1.0.3/6.1.1.3 Install (SBV-44044 / BID-66766)
vuldb·2026-05-11·CVSS 4.3
CVE-2014-2458 [MEDIUM] Oracle Agile Product Lifecycle 6.1.0.3/6.1.1.3 Install (SBV-44044 / BID-66766)
A vulnerability classified as problematic has been found in Oracle Agile Product Lifecycle 6.1.0.3/6.1.1.3. This issue affects some unknown processing of the component Install Handler. This manipulation causes an unknown weakness.
This vulnerability is tracked as CVE-2014-2458. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
GHSA
GHSA-9qqj-ph57-5qmh: Unspecified vulnerability in the Oracle Agile Product Lifecycle component in Oracle Supply Chain Products Suite 6
ghsa_unreviewed·2022-05-17
CVE-2014-2458 [MEDIUM] GHSA-9qqj-ph57-5qmh: Unspecified vulnerability in the Oracle Agile Product Lifecycle component in Oracle Supply Chain Products Suite 6
Unspecified vulnerability in the Oracle Agile Product Lifecycle component in Oracle Supply Chain Products Suite 6.1.0.3 and 6.1.1.3 allows remote attackers to affect integrity via unknown vectors related to Install.
OSV
firefox regression
osv·2015-01-27·CVSS 7.5
firefox regression
firefox regression
USN-2458-1 fixed vulnerabilities in Firefox. This update introduced a
regression which could make websites that use CSP fail to load under some
circumstances. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Christian Holler, Patrick McManus, Christoph Diehl, Gary Kwong, Jesse
Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-8634, CVE-2014-8635)
Bobby Holley discovered that some DOM objects with certain properties
can
OSV
ubufox update
osv·2015-01-14·CVSS 7.5
ubufox update
ubufox update
USN-2458-1 fixed vulnerabilities in Firefox. This update provides the
corresponding version of Ubufox.
Original advisory details:
Christian Holler, Patrick McManus, Christoph Diehl, Gary Kwong, Jesse
Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-8634, CVE-2014-8635)
Bobby Holley discovered that some DOM objects with certain properties
can bypass XrayWrappers in some circumstances. If a user were tricked in
to opening a specially crafted website, an attacker could po
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-04-16
Published