Use-after-free vulnerability in the nsDocLoader::OnProgress function in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allows remote attackers to execute arbitrary code via vectors that trigger a FireOnStateChange event.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Firefox | Mozilla | * | 30.0 (including) |
| Firefox | Mozilla | 24.0 (including) | 24.0 (including) |
| Firefox | Mozilla | 24.0.1 (including) | 24.0.1 (including) |
| Firefox | Mozilla | 24.0.2 (including) | 24.0.2 (including) |
| Firefox | Mozilla | 24.1.0 (including) | 24.1.0 (including) |
| Firefox | Mozilla | 24.1.1 (including) | 24.1.1 (including) |
| Firefox_esr | Mozilla | 24.2 (including) | 24.2 (including) |
| Firefox_esr | Mozilla | 24.3 (including) | 24.3 (including) |
| Firefox_esr | Mozilla | 24.4 (including) | 24.4 (including) |
| Firefox_esr | Mozilla | 24.5 (including) | 24.5 (including) |
| Firefox_esr | Mozilla | 24.6 (including) | 24.6 (including) |
| Thunderbird | Mozilla | * | 24.6 (including) |
| Thunderbird | Mozilla | 24.0 (including) | 24.0 (including) |
| Thunderbird | Mozilla | 24.0.1 (including) | 24.0.1 (including) |
| Thunderbird | Mozilla | 24.1 (including) | 24.1 (including) |
| Thunderbird | Mozilla | 24.1.1 (including) | 24.1.1 (including) |
| Thunderbird | Mozilla | 24.2 (including) | 24.2 (including) |
| Thunderbird | Mozilla | 24.3 (including) | 24.3 (including) |
| Thunderbird | Mozilla | 24.4 (including) | 24.4 (including) |
| Thunderbird | Mozilla | 24.5 (including) | 24.5 (including) |
| Red Hat Enterprise Linux 5 | RedHat | thunderbird-0:24.7.0-1.el5_10 | * |
| Red Hat Enterprise Linux 5 | RedHat | firefox-0:24.7.0-1.el5_10 | * |
| Red Hat Enterprise Linux 6 | RedHat | thunderbird-0:24.7.0-1.el6_5 | * |
| Red Hat Enterprise Linux 6 | RedHat | firefox-0:24.7.0-1.el6_5 | * |
| Red Hat Enterprise Linux 7 | RedHat | firefox-0:24.7.0-1.el7_0 | * |
| Red Hat Enterprise Linux 7 | RedHat | xulrunner-0:24.7.0-1.el7_0 | * |
| Firefox | Ubuntu | devel | * |
| Firefox | Ubuntu | lucid | * |
| Firefox | Ubuntu | precise | * |
| Firefox | Ubuntu | trusty | * |
| Firefox | Ubuntu | upstream | * |
| Thunderbird | Ubuntu | devel | * |
| Thunderbird | Ubuntu | lucid | * |
| Thunderbird | Ubuntu | precise | * |
| Thunderbird | Ubuntu | trusty | * |
| Thunderbird | Ubuntu | upstream | * |