5.5

CVE-2014-1496

Exploit
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version < 28.0
Mozilla ≫ Firefox Version >= 24.0 < 24.4
Mozilla ≫ Seamonkey Version < 2.25
Mozilla ≫ Thunderbird Version < 24.4
Suse ≫ Suse Linux Enterprise Desktop Version 11 Update sp3
Suse ≫ Suse Linux Enterprise Server Version 11 Update sp3
Suse ≫ Suse Linux Enterprise Server Version 11 Update sp3 SwPlatform vmware
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.295
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
NIST 1.9 3.4 2.9
AV:L/AC:M/Au:N/C:N/I:P/A:N
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
Third Party Advisory
https://security.gentoo.org/glsa/201504-01
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00016.html
Third Party Advisory
Mailing List
http://www.mozilla.org/security/announce/2014/mfsa2014-16.html
Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=925747
Vendor Advisory
Exploit
Issue Tracking