10
CVSSv2

CVE-2014-1551

Published: 23/07/2014 Updated: 07/01/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Use-after-free vulnerability in the FontTableRec destructor in Mozilla Firefox prior to 31.0, Firefox ESR 24.x prior to 24.7, and Thunderbird prior to 24.7 on Windows allows remote malicious users to execute arbitrary code via crafted use of fonts in MathML content, leading to improper handling of a DirectWrite font-face object.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox_esr 24.6

mozilla thunderbird 24.2

mozilla thunderbird 24.3

mozilla firefox_esr 24.2

mozilla firefox_esr 24.3

mozilla thunderbird 24.0

mozilla thunderbird 24.0.1

mozilla firefox_esr 24.0.1

mozilla firefox_esr 24.0.2

mozilla firefox

mozilla thunderbird

mozilla thunderbird 24.5

mozilla thunderbird 24.4

mozilla firefox_esr 24.0

mozilla firefox_esr 24.4

mozilla firefox_esr 24.5

mozilla thunderbird 24.1

mozilla thunderbird 24.1.1

mozilla firefox_esr 24.1.0

mozilla firefox_esr 24.1.1

Vendor Advisories

Mozilla Foundation Security Advisory 2014-59 Use-after-free in DirectWrite font handling Announced July 22, 2014 Reporter James Kitchener Impact Critical Products Firefox, Firefox ESR, Thunderbird Fixed in ...