9.3
CVSSv2

CVE-2014-1522

Published: 30/04/2014 Updated: 14/08/2020
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox prior to 29.0 and SeaMonkey prior to 2.26 allows remote malicious users to execute arbitrary code or cause a denial of service (out-of-bounds read, memory corruption, and application crash) via crafted content.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 19

canonical ubuntu linux 12.04

canonical ubuntu linux 12.10

canonical ubuntu linux 13.10

canonical ubuntu linux 14.04

opensuse opensuse 12.3

opensuse opensuse 13.1

mozilla firefox

mozilla seamonkey

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2014-36 Web Audio memory corruption issues Announced April 29, 2014 Reporter Ash Impact High Products Firefox, SeaMonkey Fixed in Firefox 29 ...
The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 290 and SeaMonkey before 226 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read, memory corruption, and application crash) via crafted content ...