5.5
CVE-2014-1496
- EPSS 0.38%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Thunderbird Version < 24.4
Suse ≫ Suse Linux Enterprise Software Development Kit Version 11.0 Update sp3
Suse ≫ Suse Linux Enterprise Desktop Version 11 Update sp3
Suse ≫ Suse Linux Enterprise Server Version 11 Update sp3
Suse ≫ Suse Linux Enterprise Server Version 11 Update sp3 SwPlatform vmware
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.38% | 0.295 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
| NIST | 1.9 | 3.4 | 2.9 |
AV:L/AC:M/Au:N/C:N/I:P/A:N
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
https://security.gentoo.org/glsa/201504-01
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00016.html
http://www.mozilla.org/security/announce/2014/mfsa2014-16.html
https://bugzilla.mozilla.org/show_bug.cgi?id=925747