PT-2014-1486 · Mozilla+3 · Firefox+3

Publicado

2014-06-10

·

Atualizado

2024-12-12

·

CVE-2014-1540

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 30.0
Description The issue allows a remote attacker to execute arbitrary code or cause a denial of service due to a use-after-free vulnerability in the nsEventListenerManager::CompileEventHandlerInternal function. This can be achieved through specially crafted web content, potentially leading to heap memory corruption.
Recommendations For versions prior to 30.0, update to version 30.0 or later to resolve the issue. As a temporary workaround, consider restricting access to web content that could potentially exploit this vulnerability until a patch is applied.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1978
BDU:2015-00452
BDU:2015-00679
CVE-2014-1540
MGASA-2014-0419
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
USN-2243-1

Produtos afetados

Alt Linux
Firefox
Suse
Ubuntu