HIGH · 10.0

CVE-2014-1512

Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows re...

Vulnerability Description

Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary code by triggering extensive memory consumption while garbage collection is occurring, as demonstrated by improper handling of BumpChunk objects.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MozillaFirefox< 28.0
MozillaSeamonkey< 2.25
MozillaThunderbird< 24.4
DebianDebian Linux7.0
CanonicalUbuntu Linux12.04
RedhatEnterprise Linux Desktop5.0
RedhatEnterprise Linux Eus6.5
RedhatEnterprise Linux Server5.0
RedhatEnterprise Linux Server Aus6.5
RedhatEnterprise Linux Server Eus6.5
RedhatEnterprise Linux Server Tus6.5
RedhatEnterprise Linux Workstation5.0
SuseSuse Linux Enterprise Software Development Kit11.0
OpensuseOpensuse11.4
SuseSuse Linux Enterprise Desktop11
SuseSuse Linux Enterprise Server11

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-1512?

CVE-2014-1512 is a vulnerability with a CVSS score of 10.0 (HIGH). Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows re...

How severe is CVE-2014-1512?

CVE-2014-1512 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-1512?

Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Seamonkey, Mozilla Thunderbird, Debian Debian Linux, Canonical Ubuntu Linux.