10

CVE-2014-1550

Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging incorrect Web Audio control-message ordering.

Data is provided by the National Vulnerability Database (NVD)
MozillaFirefox Version <= 30.0
MozillaThunderbird Version <= 24.7
MozillaThunderbird Version24.0
MozillaThunderbird Version24.0.1
MozillaThunderbird Version24.1
MozillaThunderbird Version24.1.1
MozillaThunderbird Version24.2
MozillaThunderbird Version24.3
MozillaThunderbird Version24.4
MozillaThunderbird Version24.5
MozillaThunderbird Version24.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.98% 0.853
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C