CVE-2014-1567

critical

Description

Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows remote attackers to execute arbitrary code via text that is improperly handled during the interaction between directionality resolution and layout.

References

https://security.gentoo.org/glsa/201504-01

https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-1643

https://bugzilla.mozilla.org/show_bug.cgi?id=1037641

http://www.securitytracker.com/id/1030794

http://www.securitytracker.com/id/1030793

http://www.securityfocus.com/bid/69520

http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html

http://www.mozilla.org/security/announce/2014/mfsa2014-72.html

http://www.debian.org/security/2014/dsa-3028

http://www.debian.org/security/2014/dsa-3018

http://secunia.com/advisories/61390

http://secunia.com/advisories/61114

http://secunia.com/advisories/60186

http://secunia.com/advisories/60148

http://lists.opensuse.org/opensuse-updates/2014-09/msg00011.html

http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html

http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00024.html

http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00012.html

http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00007.html

http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00005.html

http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00003.html

Details

Source: Mitre, NVD

Published: 2014-09-03

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.04943