CVE-2014-1508
9.1
CRITICAL · CVSS 3.1 · EPSS 4.3% (pctl 91)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process memory, cause a denial of service (out-of-bounds read and application crash), or possibly bypass the Same Origin Policy via vectors involving MathML polygon rendering.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
| EPSS | 4.27% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-125 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2014-03-19 |
| Last modified | 2026-06-17 |
Affected (16)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| debian | debian linux |
| mozilla | firefox |
| mozilla | seamonkey |
| mozilla | thunderbird |
| opensuse | opensuse |
| redhat | enterprise linux desktop |
| redhat | enterprise linux eus |
| redhat | enterprise linux server |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server eus |
| redhat | enterprise linux server tus |
| redhat | enterprise linux workstation |
| suse | suse linux enterprise desktop |
| suse | suse linux enterprise server |
| suse | suse linux enterprise software development kit |
References
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00016.html
- http://rhn.redhat.com/errata/RHSA-2014-0310.html
- http://rhn.redhat.com/errata/RHSA-2014-0316.html
- http://www.debian.org/security/2014/dsa-2881
- http://www.debian.org/security/2014/dsa-2911
- http://www.mozilla.org/security/announce/2014/mfsa2014-26.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/66426
- http://www.ubuntu.com/usn/USN-2151-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=963198
- https://security.gentoo.org/glsa/201504-01
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00016.html
- http://rhn.redhat.com/errata/RHSA-2014-0310.html
- http://rhn.redhat.com/errata/RHSA-2014-0316.html
→ the Explorer · watch your stack · NVD