CVE Vulnerabilities

CVE-2014-1541

Published: Jun 11, 2014 | Modified: Dec 28, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Use-after-free vulnerability in the RefreshDriverTimer::TickDriver function in the SMIL Animation Controller in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted web content.

Affected Software

Name Vendor Start Version End Version
Thunderbird Mozilla * 24.5 (including)
Thunderbird Mozilla 24.0 (including) 24.0 (including)
Thunderbird Mozilla 24.0.1 (including) 24.0.1 (including)
Thunderbird Mozilla 24.1 (including) 24.1 (including)
Thunderbird Mozilla 24.1.1 (including) 24.1.1 (including)
Thunderbird Mozilla 24.2 (including) 24.2 (including)
Thunderbird Mozilla 24.3 (including) 24.3 (including)
Thunderbird Mozilla 24.4 (including) 24.4 (including)
Red Hat Enterprise Linux 5 RedHat firefox-0:24.6.0-1.el5_10 *
Red Hat Enterprise Linux 5 RedHat thunderbird-0:24.6.0-1.el5_10 *
Red Hat Enterprise Linux 6 RedHat firefox-0:24.6.0-1.el6_5 *
Red Hat Enterprise Linux 6 RedHat thunderbird-0:24.6.0-1.el6_5 *
Red Hat Enterprise Linux 7 RedHat firefox-0:24.6.0-1.el7_0 *
Red Hat Enterprise Linux 7 RedHat xulrunner-0:24.6.0-1.el7_0 *
Firefox Ubuntu devel *
Firefox Ubuntu lucid *
Firefox Ubuntu precise *
Firefox Ubuntu saucy *
Firefox Ubuntu trusty *
Firefox Ubuntu upstream *
Thunderbird Ubuntu devel *
Thunderbird Ubuntu lucid *
Thunderbird Ubuntu precise *
Thunderbird Ubuntu saucy *
Thunderbird Ubuntu trusty *
Thunderbird Ubuntu upstream *

References