Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-1532

Опубликовано: 30 апр. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to host resolution.

РелизСтатусПримечание
devel

not-affected

29.0+build1-0ubuntu0.14.04.2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [29.0+build1-0ubuntu0.14.04.2]]
lucid

ignored

end of life
precise

released

29.0+build1-0ubuntu0.12.04.2
quantal

released

29.0+build1-0ubuntu0.12.10.3
saucy

released

29.0+build1-0ubuntu0.13.10.3
trusty

released

29.0+build1-0ubuntu0.14.04.2
trusty/esm

DNE

trusty was released [29.0+build1-0ubuntu0.14.04.2]
upstream

released

29.0

Показывать по

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:24.5.0+build1-0ubuntu0.14.04.1]]
lucid

ignored

end of life
precise

released

1:24.5.0+build1-0ubuntu0.12.04.1
quantal

released

1:24.5.0+build1-0ubuntu0.12.10.1
saucy

released

1:24.5.0+build1-0ubuntu0.13.10.1
trusty

released

1:24.5.0+build1-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [1:24.5.0+build1-0ubuntu0.14.04.1]
upstream

released

24.5.0

Показывать по

EPSS

Процентиль: 87%
0.03612
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

redhat
больше 11 лет назад

Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to host resolution.

CVSS3: 9.8
nvd
больше 11 лет назад

Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to host resolution.

CVSS3: 9.8
debian
больше 11 лет назад

Use-after-free vulnerability in the nsHostResolver::ConditionallyRefre ...

CVSS3: 9.8
github
около 3 лет назад

Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to host resolution.

fstec
больше 11 лет назад

Уязвимость программного пакета SeaMonkey, позволяющая удаленному злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании

EPSS

Процентиль: 87%
0.03612
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3