CVE-2014-1513: High severity Mozilla Firefox vulnerability
TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not prevent a zero-length transition during use of an ArrayBuffer object, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based out-of-bounds write or read) via a crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1513?
CVE-2014-1513 has a high severity due to the potential for remote code execution and denial of service.
How do I fix CVE-2014-1513?
To fix CVE-2014-1513, update your Mozilla Firefox, Firefox ESR, Thunderbird, or SeaMonkey to the latest version.
Which software versions are affected by CVE-2014-1513?
CVE-2014-1513 affects Mozilla Firefox versions before 28.0, Firefox ESR versions before 24.4, Thunderbird versions before 24.4, and SeaMonkey versions before 2.25.
Can CVE-2014-1513 be exploited by an attacker?
Yes, an attacker can exploit CVE-2014-1513 to execute arbitrary code on the victim's machine.
What types of attacks can result from CVE-2014-1513?
CVE-2014-1513 can allow for remote code execution, potentially leading to system compromise or denial of service.