PT-2014-1486 · Mozilla+3 · Firefox+3

Published

2014-06-10

·

Updated

2024-12-12

·

CVE-2014-1540

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 30.0
Description The issue allows a remote attacker to execute arbitrary code or cause a denial of service due to a use-after-free vulnerability in the nsEventListenerManager::CompileEventHandlerInternal function. This can be achieved through specially crafted web content, potentially leading to heap memory corruption.
Recommendations For versions prior to 30.0, update to version 30.0 or later to resolve the issue. As a temporary workaround, consider restricting access to web content that could potentially exploit this vulnerability until a patch is applied.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1978
BDU:2015-00452
BDU:2015-00679
CVE-2014-1540
MGASA-2014-0419
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
USN-2243-1

Affected Products

Alt Linux
Firefox
Suse
Ubuntu