Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows remote attackers to execute arbitrary code via text that is improperly handled during the interaction between directionality resolution and layout.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 02:04
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00003.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00005.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00007.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00012.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00024.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html - | |
References | () http://lists.opensuse.org/opensuse-updates/2014-09/msg00011.html - | |
References | () http://secunia.com/advisories/60148 - | |
References | () http://secunia.com/advisories/60186 - | |
References | () http://secunia.com/advisories/61114 - | |
References | () http://secunia.com/advisories/61390 - | |
References | () http://www.debian.org/security/2014/dsa-3018 - | |
References | () http://www.debian.org/security/2014/dsa-3028 - | |
References | () http://www.mozilla.org/security/announce/2014/mfsa2014-72.html - Vendor Advisory | |
References | () http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html - | |
References | () http://www.securityfocus.com/bid/69520 - | |
References | () http://www.securitytracker.com/id/1030793 - | |
References | () http://www.securitytracker.com/id/1030794 - | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1037641 - | |
References | () https://security.gentoo.org/glsa/201504-01 - |
21 Oct 2024, 13:55
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:mozilla:firefox_esr:24.0:*:*:*:*:*:*:* |
cpe:2.3:a:mozilla:firefox:24.0:*:*:*:*:*:*:* |
21 Oct 2024, 13:11
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:mozilla:firefox_esr:24.1.1:*:*:*:*:*:*:* |
cpe:2.3:a:mozilla:firefox:24.1.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:24.1.0:*:*:*:*:*:*:* |
Information
Published : 2014-09-03 10:55
Updated : 2024-11-21 02:04
NVD link : CVE-2014-1567
Mitre link : CVE-2014-1567
CVE.ORG link : CVE-2014-1567
JSON object : View
Products Affected
mozilla
- firefox
- thunderbird
- firefox_esr
CWE