CVE-2014-8641

CWE-416Use After Free7 documents7 sources
Severity
7.5HIGH
EPSS
1.5%
top 18.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14
Latest updateMay 17

Description

Use-after-free vulnerability in the WebRTC implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, and SeaMonkey before 2.32 allows remote attackers to execute arbitrary code via crafted track data.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages4 packages

NVDmozilla/firefox34.0.5+4
Ubuntufirefox< 35.0+build3-0ubuntu0.14.04.2

🔴Vulnerability Details

3
GHSA
GHSA-ccgg-x9xx-x49v: Use-after-free vulnerability in the WebRTC implementation in Mozilla Firefox before 352022-05-17
CVEList
CVE-2014-8641: Use-after-free vulnerability in the WebRTC implementation in Mozilla Firefox before 352015-01-14
OSV
CVE-2014-8641: Use-after-free vulnerability in the WebRTC implementation in Mozilla Firefox before 352015-01-14

📋Vendor Advisories

2
Ubuntu
Firefox vulnerabilities2015-01-14
Red Hat
Mozilla: Read-after-free in WebRTC (MFSA 2015-06)2015-01-13

💬Community

1
Bugzilla
CVE-2014-8641 Mozilla: Read-after-free in WebRTC (MFSA 2015-06)2015-01-12