Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 1 min 106 bronnen 1 kritiek 1 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2014-1512

HIGH · 10.0 CVSS Gepubliceerd: CWE-416

Beschrijving

Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary code by triggering extensive memory consumption while garbage collection is occurring, as demonstrated by improper handling of BumpChunk objects.

Vendors

Mozilla Debian Canonical Redhat Suse Opensuse

Affected products

Firefox Seamonkey Thunderbird Debian Linux Ubuntu Linux Enterprise Linux Desktop Enterprise Linux Eus Enterprise Linux Server Enterprise Linux Server Aus Enterprise Linux Server Eus Enterprise Linux Server Tus Enterprise Linux Workstation Suse Linux Enterprise Software Development Kit Opensuse Suse Linux Enterprise Desktop Suse Linux Enterprise Server

References