6.8
CVSSv2

CVE-2014-1594

Published: 11/12/2014 Updated: 24/12/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Mozilla Firefox prior to 34.0, Firefox ESR 31.x prior to 31.3, Thunderbird prior to 31.3, and SeaMonkey prior to 2.31 might allow remote malicious users to execute arbitrary code by leveraging an incorrect cast from the BasicThebesLayer data type to the BasicContainerLayer data type.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla thunderbird

mozilla firefox

mozilla firefox esr

mozilla seamonkey

Vendor Advisories

Several security issues were fixed in Thunderbird ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Multiple security issues have been found in Icedove, Debian's version of the Mozilla Thunderbird mail and news client: Multiple memory safety errors, buffer overflows, use-after-frees and other implementation errors may lead to the execution of arbitrary code, the bypass of security restrictions or denial of service For the stable distribution (wh ...
Multiple security issues have been found in Iceweasel, Debian's version of the Mozilla Firefox web browser: Multiple memory safety errors, buffer overflows, use-after-frees and other implementation errors may lead to the execution of arbitrary code, the bypass of security restrictions or denial of service For the stable distribution (wheezy), thes ...
Mozilla Foundation Security Advisory 2014-89 Bad casting from the BasicThebesLayer to BasicContainerLayer Announced December 2, 2014 Reporter Byoungyoung Lee, Chengyu Song, Taesoo Kim Impact High Products Firefox, Firefox ES ...