9.3

CVE-2014-1555

Use-after-free vulnerability in the nsDocLoader::OnProgress function in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allows remote attackers to execute arbitrary code via vectors that trigger a FireOnStateChange event.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MozillaFirefox Version <= 30.0
MozillaFirefox Version24.0
MozillaFirefox Version24.1.0
MozillaFirefox Version24.1.1
MozillaFirefox ESR Version24.0.1
MozillaFirefox ESR Version24.0.2
MozillaFirefox ESR Version24.2
MozillaFirefox ESR Version24.3
MozillaFirefox ESR Version24.4
MozillaFirefox ESR Version24.5
MozillaFirefox ESR Version24.6
MozillaThunderbird Version <= 24.6
MozillaThunderbird Version24.0
MozillaThunderbird Version24.0.1
MozillaThunderbird Version24.1
MozillaThunderbird Version24.1.1
MozillaThunderbird Version24.2
MozillaThunderbird Version24.3
MozillaThunderbird Version24.4
MozillaThunderbird Version24.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.81% 0.811
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C