5.5
CVSSv3

CVE-2014-1496

Published: 19/03/2014 Updated: 05/08/2020
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Mozilla Firefox prior to 28.0, Firefox ESR 24.x prior to 24.4, Thunderbird prior to 24.4, and SeaMonkey prior to 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla firefox esr

mozilla seamonkey

mozilla thunderbird

suse suse linux enterprise software development kit 11.0

suse suse linux enterprise desktop 11

suse suse linux enterprise server 11

Vendor Advisories

Mozilla Foundation Security Advisory 2014-16 Files extracted during updates are not always read only Announced March 18, 2014 Reporter Ash Impact Moderate Products Firefox, Firefox ESR, SeaMonkey, Thunderbird Fixed in ...