CVE
- Id
- 68873
- CVE No.
- CVE-2014-1578
- Status
- Candidate
- Description
- The get_tile function in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly execute arbitrary code via WebM frames with invalid tile sizes that are improperly handled in buffering operations during video playback.
- Phase
- Assigned (20140116)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
662606 | 68873 | CVE-2014-1578 | CONFIRM:http://www.mozilla.org/security/announce/2014/mfsa2014-77.html | View |
662607 | 68873 | CVE-2014-1578 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=1063327 | View |
662608 | 68873 | CVE-2014-1578 | CONFIRM:https://advisories.mageia.org/MGASA-2014-0421.html | View |
662609 | 68873 | CVE-2014-1578 | CONFIRM:http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html | View |
662610 | 68873 | CVE-2014-1578 | DEBIAN:DSA-3050 | View |
662611 | 68873 | CVE-2014-1578 | URL:http://www.debian.org/security/2014/dsa-3050 | View |
662612 | 68873 | CVE-2014-1578 | DEBIAN:DSA-3061 | View |
662613 | 68873 | CVE-2014-1578 | URL:http://www.debian.org/security/2014/dsa-3061 | View |
662614 | 68873 | CVE-2014-1578 | FEDORA:FEDORA-2014-13042 | View |
662615 | 68873 | CVE-2014-1578 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141085.html | View |
662616 | 68873 | CVE-2014-1578 | FEDORA:FEDORA-2014-14084 | View |
662617 | 68873 | CVE-2014-1578 | URL:http://lists.fedoraproject.org/pipermail/package-announce/2014-November/141796.html | View |
662618 | 68873 | CVE-2014-1578 | GENTOO:GLSA-201504-01 | View |
662619 | 68873 | CVE-2014-1578 | URL:https://security.gentoo.org/glsa/201504-01 | View |
662620 | 68873 | CVE-2014-1578 | REDHAT:RHSA-2014:1635 | View |
662621 | 68873 | CVE-2014-1578 | URL:http://rhn.redhat.com/errata/RHSA-2014-1635.html | View |
662622 | 68873 | CVE-2014-1578 | REDHAT:RHSA-2014:1647 | View |
662623 | 68873 | CVE-2014-1578 | URL:http://rhn.redhat.com/errata/RHSA-2014-1647.html | View |
662624 | 68873 | CVE-2014-1578 | SUSE:openSUSE-SU-2014:1343 | View |
662625 | 68873 | CVE-2014-1578 | URL:http://lists.opensuse.org/opensuse-updates/2014-11/msg00000.html | View |
662626 | 68873 | CVE-2014-1578 | SUSE:openSUSE-SU-2014:1346 | View |
662627 | 68873 | CVE-2014-1578 | URL:http://lists.opensuse.org/opensuse-updates/2014-11/msg00003.html | View |
662628 | 68873 | CVE-2014-1578 | SUSE:openSUSE-SU-2014:1344 | View |
662629 | 68873 | CVE-2014-1578 | URL:http://lists.opensuse.org/opensuse-updates/2014-11/msg00001.html | View |
662630 | 68873 | CVE-2014-1578 | SUSE:openSUSE-SU-2014:1345 | View |
662631 | 68873 | CVE-2014-1578 | URL:http://lists.opensuse.org/opensuse-updates/2014-11/msg00002.html | View |
662632 | 68873 | CVE-2014-1578 | SUSE:openSUSE-SU-2015:0138 | View |
662633 | 68873 | CVE-2014-1578 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00024.html | View |
662634 | 68873 | CVE-2014-1578 | SUSE:openSUSE-SU-2015:1266 | View |
662635 | 68873 | CVE-2014-1578 | URL:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html | View |
662636 | 68873 | CVE-2014-1578 | UBUNTU:USN-2372-1 | View |
662637 | 68873 | CVE-2014-1578 | URL:http://www.ubuntu.com/usn/USN-2372-1 | View |
662638 | 68873 | CVE-2014-1578 | UBUNTU:USN-2373-1 | View |
662639 | 68873 | CVE-2014-1578 | URL:http://www.ubuntu.com/usn/USN-2373-1 | View |
662640 | 68873 | CVE-2014-1578 | BID:70428 | View |
662641 | 68873 | CVE-2014-1578 | URL:http://www.securityfocus.com/bid/70428 | View |
662642 | 68873 | CVE-2014-1578 | SECTRACK:1031028 | View |
662643 | 68873 | CVE-2014-1578 | URL:http://www.securitytracker.com/id/1031028 | View |
662644 | 68873 | CVE-2014-1578 | SECTRACK:1031030 | View |
662645 | 68873 | CVE-2014-1578 | URL:http://www.securitytracker.com/id/1031030 | View |
662646 | 68873 | CVE-2014-1578 | SECUNIA:61387 | View |
662647 | 68873 | CVE-2014-1578 | URL:http://secunia.com/advisories/61387 | View |
662648 | 68873 | CVE-2014-1578 | SECUNIA:61854 | View |
662649 | 68873 | CVE-2014-1578 | URL:http://secunia.com/advisories/61854 | View |
662650 | 68873 | CVE-2014-1578 | SECUNIA:62021 | View |
662651 | 68873 | CVE-2014-1578 | URL:http://secunia.com/advisories/62021 | View |
662652 | 68873 | CVE-2014-1578 | SECUNIA:62022 | View |
662653 | 68873 | CVE-2014-1578 | URL:http://secunia.com/advisories/62022 | View |
662654 | 68873 | CVE-2014-1578 | SECUNIA:62023 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
16023 | JVNDB-2014-004898 | Mozilla Firefox の content/base/src/nsDocument.cpp におけるローカルカメラから重要な情報を取得される脆弱性 | Mozilla Firefox の content/base/src/nsDocument.cpp は、WebRTC によるビデオ共有が発生しているかどうかを考慮しないため、IFRAME の特定の状況におけるローカルカメラから重要な情報を取得される脆弱性が存在します。 | CVE-2014-1586 | 68873 | 5 | http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-004898.html | View |