CVE-2014-1514
- EPSS 4.17%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a copy operation, which allows remote attackers to ex...
- EPSS 17.91%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary code by trigge...
- EPSS 1.47%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and app...
CVE-2014-1496
- EPSS 0.06%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
CVE-2014-1497
- EPSS 0.5%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause...
CVE-2014-1505
- EPSS 0.54%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the S...
CVE-2014-1508
- EPSS 0.99%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process memory, cause a denial of...
CVE-2014-1509
- EPSS 0.81%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25, allows remote attackers to execute arbitrary code via a ...
CVE-2014-1510
- EPSS 77.56%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment t...
CVE-2014-1511
- EPSS 75.96%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.