First published: Thu Dec 11 2014(Updated: )
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=33.0 | |
Mozilla Firefox ESR | <=31.2 | |
Mozilla SeaMonkey | <=2.30 | |
Mozilla Thunderbird | <=31.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1587 is considered a critical vulnerability due to its potential to cause denial of service and execute arbitrary code.
To mitigate CVE-2014-1587, users should update their affected Mozilla Firefox, Firefox ESR, Thunderbird, or SeaMonkey to the latest versions.
CVE-2014-1587 affects Mozilla Firefox versions prior to 34.0, Firefox ESR versions prior to 31.3, Thunderbird versions prior to 31.3, and SeaMonkey versions prior to 2.31.
CVE-2014-1587 can allow remote attackers to crash the application or potentially execute arbitrary code on the victim's system.
If your software has been updated to versions beyond those specified in CVE-2014-1587, the risk associated with this vulnerability should be mitigated.