CVE
- Id
- 68833
- CVE No.
- CVE-2014-1538
- Status
- Candidate
- Description
- Use-after-free vulnerability in the nsTextEditRules::CreateMozBR function in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
- Phase
- Assigned (20140116)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 661605 | 68833 | CVE-2014-1538 | CONFIRM:http://www.mozilla.org/security/announce/2014/mfsa2014-49.html | View |
| 661606 | 68833 | CVE-2014-1538 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=1005584 | View |
| 661607 | 68833 | CVE-2014-1538 | CONFIRM:http://linux.oracle.com/errata/ELSA-2014-0741.html | View |
| 661608 | 68833 | CVE-2014-1538 | CONFIRM:http://linux.oracle.com/errata/ELSA-2014-0742.html | View |
| 661609 | 68833 | CVE-2014-1538 | CONFIRM:http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html | View |
| 661610 | 68833 | CVE-2014-1538 | GENTOO:GLSA-201504-01 | View |
| 661611 | 68833 | CVE-2014-1538 | URL:https://security.gentoo.org/glsa/201504-01 | View |
| 661612 | 68833 | CVE-2014-1538 | SUSE:openSUSE-SU-2014:0855 | View |
| 661613 | 68833 | CVE-2014-1538 | URL:http://lists.opensuse.org/opensuse-updates/2014-07/msg00001.html | View |
| 661614 | 68833 | CVE-2014-1538 | SUSE:openSUSE-SU-2014:0858 | View |
| 661615 | 68833 | CVE-2014-1538 | URL:http://lists.opensuse.org/opensuse-updates/2014-07/msg00004.html | View |
| 661616 | 68833 | CVE-2014-1538 | BID:67976 | View |
| 661617 | 68833 | CVE-2014-1538 | URL:http://www.securityfocus.com/bid/67976 | View |
| 661618 | 68833 | CVE-2014-1538 | SECTRACK:1030386 | View |
| 661619 | 68833 | CVE-2014-1538 | URL:http://www.securitytracker.com/id/1030386 | View |
| 661620 | 68833 | CVE-2014-1538 | SECTRACK:1030388 | View |
| 661621 | 68833 | CVE-2014-1538 | URL:http://www.securitytracker.com/id/1030388 | View |
| 661622 | 68833 | CVE-2014-1538 | SECUNIA:58984 | View |
| 661623 | 68833 | CVE-2014-1538 | URL:http://secunia.com/advisories/58984 | View |
| 661624 | 68833 | CVE-2014-1538 | SECUNIA:59052 | View |
| 661625 | 68833 | CVE-2014-1538 | URL:http://secunia.com/advisories/59052 | View |
| 661626 | 68833 | CVE-2014-1538 | SECUNIA:59149 | View |
| 661627 | 68833 | CVE-2014-1538 | URL:http://secunia.com/advisories/59149 | View |
| 661628 | 68833 | CVE-2014-1538 | SECUNIA:59150 | View |
| 661629 | 68833 | CVE-2014-1538 | URL:http://secunia.com/advisories/59150 | View |
| 661630 | 68833 | CVE-2014-1538 | SECUNIA:59165 | View |
| 661631 | 68833 | CVE-2014-1538 | URL:http://secunia.com/advisories/59165 | View |
| 661632 | 68833 | CVE-2014-1538 | SECUNIA:59169 | View |
| 661633 | 68833 | CVE-2014-1538 | URL:http://secunia.com/advisories/59169 | View |
| 661634 | 68833 | CVE-2014-1538 | SECUNIA:59170 | View |
| 661635 | 68833 | CVE-2014-1538 | URL:http://secunia.com/advisories/59170 | View |
| 661636 | 68833 | CVE-2014-1538 | SECUNIA:59171 | View |
| 661637 | 68833 | CVE-2014-1538 | URL:http://secunia.com/advisories/59171 | View |
| 661638 | 68833 | CVE-2014-1538 | SECUNIA:59229 | View |
| 661639 | 68833 | CVE-2014-1538 | URL:http://secunia.com/advisories/59229 | View |
| 661640 | 68833 | CVE-2014-1538 | SECUNIA:59275 | View |
| 661641 | 68833 | CVE-2014-1538 | URL:http://secunia.com/advisories/59275 | View |
| 661642 | 68833 | CVE-2014-1538 | SECUNIA:59866 | View |
| 661643 | 68833 | CVE-2014-1538 | URL:http://secunia.com/advisories/59866 | View |
| 661644 | 68833 | CVE-2014-1538 | SECUNIA:59377 | View |
| 661645 | 68833 | CVE-2014-1538 | URL:http://secunia.com/advisories/59377 | View |
| 661646 | 68833 | CVE-2014-1538 | SECUNIA:59387 | View |
| 661647 | 68833 | CVE-2014-1538 | URL:http://secunia.com/advisories/59387 | View |
| 661648 | 68833 | CVE-2014-1538 | SECUNIA:59328 | View |
| 661649 | 68833 | CVE-2014-1538 | URL:http://secunia.com/advisories/59328 | View |
| 661650 | 68833 | CVE-2014-1538 | SECUNIA:59425 | View |
| 661651 | 68833 | CVE-2014-1538 | URL:http://secunia.com/advisories/59425 | View |
| 661652 | 68833 | CVE-2014-1538 | SECUNIA:59486 | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 14933 | JVNDB-2014-003808 | Bugzilla の jsonrpc.cgi の WebService/Server/JSONRPC.pm の JSONP エンドポイント内の response 関数におけるクロスサイトリクエストフォージェリ攻撃を実行される脆弱性 | Bugzilla の jsonrpc.cgi の WebService/Server/JSONRPC.pm の JSONP エンドポイント内の response 関数は、特定の過度に長いコールバック値を受け入れ、JSONP レスポンスの最初のバイトを制限しないため、クロスサイトリクエストフォージェリ攻撃を実行され、重要な情報を取得される脆弱性が存在します。 | CVE-2014-1546 | 68833 | 4.3 | http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-003808.html | View |