9.3
CVE-2014-1567
- EPSS 4.94%
- Veröffentlicht 03.09.2014 10:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows remote attackers to execute arbitrary code via text that is improperly handled during the interaction between directionality resolution and layout.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox ESR Version 24.2
Mozilla ≫ Firefox ESR Version 24.3
Mozilla ≫ Firefox ESR Version 24.4
Mozilla ≫ Firefox ESR Version 24.5
Mozilla ≫ Firefox ESR Version 24.6
Mozilla ≫ Firefox ESR Version 24.7
Mozilla ≫ Thunderbird Version 24.0
Mozilla ≫ Thunderbird Version 24.0.1
Mozilla ≫ Thunderbird Version 24.1
Mozilla ≫ Thunderbird Version 24.1.1
Mozilla ≫ Thunderbird Version 24.2
Mozilla ≫ Thunderbird Version 24.3
Mozilla ≫ Thunderbird Version 24.4
Mozilla ≫ Thunderbird Version 24.5
Mozilla ≫ Thunderbird Version 24.6
Mozilla ≫ Thunderbird Version 24.7
Mozilla ≫ Thunderbird Version 31.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.94% | 0.91 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
https://security.gentoo.org/glsa/201504-01
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00024.html
http://lists.opensuse.org/opensuse-updates/2014-09/msg00011.html
http://secunia.com/advisories/60148
http://secunia.com/advisories/61114
http://www.securitytracker.com/id/1030793
http://www.securitytracker.com/id/1030794
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00007.html
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00012.html
http://secunia.com/advisories/60186
http://secunia.com/advisories/61390
http://www.debian.org/security/2014/dsa-3018
http://www.debian.org/security/2014/dsa-3028
http://www.mozilla.org/security/announce/2014/mfsa2014-72.html
http://www.securityfocus.com/bid/69520
https://bugzilla.mozilla.org/show_bug.cgi?id=1037641