CVE-2014-1551: Use After Free
Use-after-free vulnerability in the FontTableRec destructor in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 on Windows allows remote attackers to execute arbitrary code via crafted use of fonts in MathML content, leading to improper handling of a DirectWrite font-face object.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1551?
CVE-2014-1551 is rated as a critical severity vulnerability due to its potential to execute arbitrary code remotely.
How do I fix CVE-2014-1551?
To fix CVE-2014-1551, update Mozilla Firefox to version 31.0 or later, and upgrade Thunderbird to version 24.7 or later.
What software is affected by CVE-2014-1551?
CVE-2014-1551 affects Mozilla Firefox versions before 31.0, Firefox ESR versions 24.x before 24.7, and Thunderbird versions before 24.7 on Windows.
Can CVE-2014-1551 be exploited through MathML content?
Yes, CVE-2014-1551 can be exploited by remote attackers via crafted use of fonts within MathML content.
Is there a workaround for CVE-2014-1551 if I cannot update immediately?
There are no official workarounds for CVE-2014-1551, so updating to the latest version is strongly recommended.