9.3
CVSSv2

CVE-2014-1540

Published: 11/06/2014 Updated: 28/12/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Use-after-free vulnerability in the nsEventListenerManager::CompileEventHandlerInternal function in the Event Listener Manager in Mozilla Firefox prior to 30.0 allows remote malicious users to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted web content.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2014-51 Use-after-free in Event Listener Manager Announced June 10, 2014 Reporter Tyson Smith, Jesse Schwartzentruber Impact Critical Products Firefox, SeaMonkey Fixed in ...
Use-after-free vulnerability in the nsEventListenerManager::CompileEventHandlerInternal function in the Event Listener Manager in Mozilla Firefox before 300 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted web content ...