10

CVE-2014-1551

Use-after-free vulnerability in the FontTableRec destructor in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 on Windows allows remote attackers to execute arbitrary code via crafted use of fonts in MathML content, leading to improper handling of a DirectWrite font-face object.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version <= 30.0
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 24.0
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 24.0.1
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 24.0.2
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 24.1.0
   Microsoft ≫ Windows
Mozilla ≫ Firefox Version 24.1.1
   Microsoft ≫ Windows
Mozilla ≫ Firefox ESR Version 24.2
   Microsoft ≫ Windows
Mozilla ≫ Firefox ESR Version 24.3
   Microsoft ≫ Windows
Mozilla ≫ Firefox ESR Version 24.4
   Microsoft ≫ Windows
Mozilla ≫ Firefox ESR Version 24.5
   Microsoft ≫ Windows
Mozilla ≫ Firefox ESR Version 24.6
   Microsoft ≫ Windows
Mozilla ≫ Thunderbird Version <= 24.6
   Microsoft ≫ Windows
Mozilla ≫ Thunderbird Version 24.0
   Microsoft ≫ Windows
Mozilla ≫ Thunderbird Version 24.0.1
   Microsoft ≫ Windows
Mozilla ≫ Thunderbird Version 24.1
   Microsoft ≫ Windows
Mozilla ≫ Thunderbird Version 24.1.1
   Microsoft ≫ Windows
Mozilla ≫ Thunderbird Version 24.2
   Microsoft ≫ Windows
Mozilla ≫ Thunderbird Version 24.3
   Microsoft ≫ Windows
Mozilla ≫ Thunderbird Version 24.4
   Microsoft ≫ Windows
Mozilla ≫ Thunderbird Version 24.5
   Microsoft ≫ Windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.68% 0.906
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
https://security.gentoo.org/glsa/201504-01
http://secunia.com/advisories/59760
http://www.securitytracker.com/id/1030619
http://www.securitytracker.com/id/1030620
http://www.mozilla.org/security/announce/2014/mfsa2014-59.html
Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1018234