CVE-2014-1541: Use After Free
Use-after-free vulnerability in the RefreshDriverTimer::TickDriver function in the SMIL Animation Controller in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted web content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1541?
CVE-2014-1541 is classified as a critical vulnerability that can lead to remote code execution or denial of service.
How do I fix CVE-2014-1541?
To fix CVE-2014-1541, update Mozilla Firefox to version 30.0 or later, or Thunderbird and Firefox ESR to versions 24.6 or later.
Which versions of software are affected by CVE-2014-1541?
CVE-2014-1541 affects Mozilla Firefox versions before 30.0, Thunderbird versions before 24.6, and Firefox ESR versions before 24.6.
What kind of attack can exploit CVE-2014-1541?
CVE-2014-1541 can be exploited through crafted content that triggers the use-after-free vulnerability, potentially allowing arbitrary code execution.
Is there any workaround for CVE-2014-1541?
There are no known workarounds for CVE-2014-1541; the recommended mitigation is to upgrade to the secure versions of the affected software.