CVE-2014-1482
RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as demonstrated by Goo Create.
- Affected products
- Alt Linux, Centos, Firefox Esr, Firefox, Red Hat, Seamonkey, Suse, Thunderbird
- Mozilla Firefox
- < 27.0, 24.3
- Mozilla Seamonkey
- < 2.24
- Mozilla Thunderbird
- < 24.3
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 6.3% (93th percentile)
- Weakness
- CWE-787
- NVD status
- Modified
- Published
- 2014-02-06
CVE-2014-1482 at NVD
No indexed exploits for CVE-2014-1482 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2014-1482 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.