CVE-2014-1577
Summary
| CVE | CVE-2014-1577 |
|---|---|
| State | PUBLISHED |
| Assigner | mozilla |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-15 10:55:06 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read, memory corruption, and application crash) via an invalid custom waveform that triggers a calculation of a negative frequency value. |
Risk And Classification
Primary CVSS: v2.0 6.4 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:P/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 30.0 | All | All | All |
| Application | Mozilla | Firefox | 31.0 | All | All | All |
| Application | Mozilla | Firefox | 31.1.0 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Thunderbird | 31.0 | All | All | All |
| Application | Mozilla | Thunderbird | 31.1.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| openSUSE-SU-2014:1346-1: moderate: update for MozillaThunderbird | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| openSUSE-SU-2014:1345-1: moderate: update for firefox, mozilla-nspr, moz | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Mozilla Firefox Bugs Let Remote Users Execute Arbitrary Code, Bypass Same Origin-Policy, and Obtain Potentially Sensitive Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| openSUSE-SU-2014:1343-1: moderate: update for MozillaThunderbird | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| USN-2372-1: Firefox vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Oracle Solaris Third Party Bulletin - April 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| openSUSE-SU-2014:1344-1: moderate: update for firefox, mozilla-nspr, moz | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Gentoo Security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Debian -- Security Information -- DSA-3061-1 icedove | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Security Advisory SA62023 - SUSE update for firefox, mozilla-nspr, and mozilla-nss - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Access Denied | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| [SECURITY] Fedora 21 Update: firefox-33.0-1.fc21 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Security Advisory SA61387 - Debian update for icedove - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-3050-1 iceweasel | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Security Advisory SA61854 - Mageia update for firefox and thunderbird - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Mozilla Thunderbird Bugs Let Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Mozilla Firefox/Thunderbird CVE-2014-1577 Out of Bounds Memory Corruption Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Security Advisory SA62022 - SUSE update for firefox, mozilla-nspr, mozilla-nss, and seamonkey - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Web Audio memory corruption issues with custom waveforms — Mozilla | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| Security Advisory SA62021 - SUSE update for MozillaThunderbird - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| USN-2373-1: Thunderbird vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [security-announce] openSUSE-SU-2015:0138-1: important: Firefox update t | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Mageia Advisory: MGASA-2014-0421 - Updated firefox and thunderbird packages fix security vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | advisories.mageia.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [SECURITY] Fedora 20 Update: firefox-33.0-1.fc20 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [security-announce] openSUSE-SU-2015:1266-1: important: Mozilla (Firefox | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.