{"api_version":"1","generated_at":"2026-07-23T10:19:27+00:00","cve":"CVE-2014-1490","urls":{"html":"https://cve.report/CVE-2014-1490","api":"https://cve.report/api/cve/CVE-2014-1490.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-1490","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-1490"},"summary":{"title":"CVE-2014-1490","description":"Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.","state":"PUBLISHED","assigner":"mozilla","published_at":"2014-02-06 05:44:25","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-362","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761","name":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"2016-10 Security Bulletin: CTPView: Multiple vulnerabilities in CTPView - Juniper Networks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2014/mfsa2014-12.html","name":"http://www.mozilla.org/security/announce/2014/mfsa2014-12.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MFSA 2014-12: NSS ticket handling issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1029721","name":"http://www.securitytracker.com/id/1029721","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Mozilla Thunderbird Multiple Bugs Let Remote Users Execute Arbitrary Code and Obtain Potentially Sensitive Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html","name":"http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] SUSE-SU-2014:0248-1: important: Security update for","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201504-01","name":"https://security.gentoo.org/glsa/201504-01","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Gentoo Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/56922","name":"http://secunia.com/advisories/56922","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Security Advisory SA56922 - SUSE update for Multiple Mozilla Packages - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/56706","name":"http://secunia.com/advisories/56706","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Security Advisory SA56706 - Cyberfox Multiple Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1029717","name":"http://www.securitytracker.com/id/1029717","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code and Obtain Potentially Sensitive Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 20 Update: thunderbird-24.3.0-1.fc20","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html","name":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Oracle VM Server for x86 Bulletin - July 2016","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 19 Update: thunderbird-24.3.0-1.fc19","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html","name":"http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Oracle Critical Patch Update - October 2014","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/56888","name":"http://secunia.com/advisories/56888","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Security Advisory SA56888 - Ubuntu update for firefox - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=930874","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=930874","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Vendor Advisory"],"title":"930874 – (CVE-2014-1490) TOCTOU, potential use-after-free in libssl's session ticket processing due to lack of lock protecting the sessionTicket field of the sid","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1029720","name":"http://www.securitytracker.com/id/1029720","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Mozilla Seamonkey Multiple Bugs Let Remote Users Execute Arbitrary Code and Obtain Potentially Sensitive Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/65335","name":"http://www.securityfocus.com/bid/65335","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Mozilla Network Security Services CVE-2014-1490 Use After Free Memory Corruption Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=930857","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=930857","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch","Vendor Advisory"],"title":"930857 – NewSessionTicket handshake message in a resumption handshake replaces cached session's ticket before handshake is finished","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/534161/100/0/threaded","name":"http://www.securityfocus.com/archive/1/534161/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html","name":"http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] openSUSE-SU-2014:0213-1: important: Mozilla updates","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html","name":"http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Oracle Critical Patch Update - July 2014","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://8pecxstudios.com/?page_id=44080","name":"https://8pecxstudios.com/?page_id=44080","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","URL Repurposed"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://secunia.com/advisories/56767","name":"http://secunia.com/advisories/56767","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Security Advisory SA56767 - Mozilla Firefox / Thunderbird / SeaMonkey Multiple Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html","name":"http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] openSUSE-SU-2014:0212-1: important: Mozilla Firefox","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/USN-2119-1","name":"http://www.ubuntu.com/usn/USN-2119-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-2119-1: Thunderbird vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html","name":"http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Oracle Critical Patch Update - January 2016","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.ubuntu.com/usn/USN-2102-2","name":"http://www.ubuntu.com/usn/USN-2102-2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-2102-2: Firefox regression | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2014/dsa-2858","name":"http://www.debian.org/security/2014/dsa-2858","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-2858-1 iceweasel","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html","name":"http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[security-announce] openSUSE-SU-2014:0419-1: important: Mozilla updates","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/56858","name":"http://secunia.com/advisories/56858","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Security Advisory SA56858 - Debian update for iceweasel - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","name":"http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Oracle Critical Patch Update - January 2015","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2014/Dec/23","name":"http://seclists.org/fulldisclosure/2014/Dec/23","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"],"title":"Full Disclosure: NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vmware.com/security/advisories/VMSA-2014-0012.html","name":"http://www.vmware.com/security/advisories/VMSA-2014-0012.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"],"title":"VMSA-2014-0012 | United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/56787","name":"http://secunia.com/advisories/56787","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Security Advisory SA56787 - Mozilla Firefox Multiple Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/90885","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/90885","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/102876","name":"http://osvdb.org/102876","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.ubuntu.com/usn/USN-2102-1","name":"http://www.ubuntu.com/usn/USN-2102-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-2102-1: Firefox vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-1490","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-1490","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"1490","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T09:42:36.290Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"USN-2119-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2119-1"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html"},{"name":"65335","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/65335"},{"name":"1029721","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1029721"},{"name":"openSUSE-SU-2014:0212","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html"},{"name":"1029717","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1029717"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/security/advisories/VMSA-2014-0012.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://8pecxstudios.com/?page_id=44080"},{"name":"56922","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/56922"},{"name":"56787","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/56787"},{"name":"1029720","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1029720"},{"name":"56858","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/56858"},{"name":"102876","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/102876"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html"},{"name":"DSA-2858","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2014/dsa-2858"},{"name":"20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/534161/100/0/threaded"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=930874"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html"},{"name":"USN-2102-2","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2102-2"},{"name":"GLSA-201504-01","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"https://security.gentoo.org/glsa/201504-01"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/2014/mfsa2014-12.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761"},{"name":"20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2014/Dec/23"},{"name":"56888","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/56888"},{"name":"FEDORA-2014-2083","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html"},{"name":"openSUSE-SU-2014:0419","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html"},{"name":"mozilla-nss-cve20141490-code-exec(90885)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/90885"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html"},{"name":"FEDORA-2014-2041","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html"},{"name":"SUSE-SU-2014:0248","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html"},{"name":"openSUSE-SU-2014:0213","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html"},{"name":"USN-2102-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2102-1"},{"name":"56767","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/56767"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=930857"},{"name":"56706","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/56706"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-02-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-09T18:57:01.000Z","orgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","shortName":"mozilla"},"references":[{"name":"USN-2119-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2119-1"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html"},{"name":"65335","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/65335"},{"name":"1029721","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1029721"},{"name":"openSUSE-SU-2014:0212","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html"},{"name":"1029717","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1029717"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/security/advisories/VMSA-2014-0012.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://8pecxstudios.com/?page_id=44080"},{"name":"56922","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/56922"},{"name":"56787","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/56787"},{"name":"1029720","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1029720"},{"name":"56858","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/56858"},{"name":"102876","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/102876"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html"},{"name":"DSA-2858","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2014/dsa-2858"},{"name":"20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/534161/100/0/threaded"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=930874"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html"},{"name":"USN-2102-2","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2102-2"},{"name":"GLSA-201504-01","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"https://security.gentoo.org/glsa/201504-01"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/2014/mfsa2014-12.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761"},{"name":"20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2014/Dec/23"},{"name":"56888","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/56888"},{"name":"FEDORA-2014-2083","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html"},{"name":"openSUSE-SU-2014:0419","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html"},{"name":"mozilla-nss-cve20141490-code-exec(90885)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/90885"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html"},{"name":"FEDORA-2014-2041","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html"},{"name":"SUSE-SU-2014:0248","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html"},{"name":"openSUSE-SU-2014:0213","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html"},{"name":"USN-2102-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-2102-1"},{"name":"56767","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/56767"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=930857"},{"name":"56706","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/56706"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"security@mozilla.org","ID":"CVE-2014-1490","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"USN-2119-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2119-1"},{"name":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html"},{"name":"65335","refsource":"BID","url":"http://www.securityfocus.com/bid/65335"},{"name":"1029721","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1029721"},{"name":"openSUSE-SU-2014:0212","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html"},{"name":"1029717","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1029717"},{"name":"http://www.vmware.com/security/advisories/VMSA-2014-0012.html","refsource":"CONFIRM","url":"http://www.vmware.com/security/advisories/VMSA-2014-0012.html"},{"name":"https://8pecxstudios.com/?page_id=44080","refsource":"CONFIRM","url":"https://8pecxstudios.com/?page_id=44080"},{"name":"56922","refsource":"SECUNIA","url":"http://secunia.com/advisories/56922"},{"name":"56787","refsource":"SECUNIA","url":"http://secunia.com/advisories/56787"},{"name":"1029720","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1029720"},{"name":"56858","refsource":"SECUNIA","url":"http://secunia.com/advisories/56858"},{"name":"102876","refsource":"OSVDB","url":"http://osvdb.org/102876"},{"name":"http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html"},{"name":"DSA-2858","refsource":"DEBIAN","url":"http://www.debian.org/security/2014/dsa-2858"},{"name":"20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/534161/100/0/threaded"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=930874","refsource":"CONFIRM","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=930874"},{"name":"http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html"},{"name":"USN-2102-2","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2102-2"},{"name":"GLSA-201504-01","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201504-01"},{"name":"http://www.mozilla.org/security/announce/2014/mfsa2014-12.html","refsource":"CONFIRM","url":"http://www.mozilla.org/security/announce/2014/mfsa2014-12.html"},{"name":"http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html"},{"name":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761","refsource":"CONFIRM","url":"http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761"},{"name":"20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities","refsource":"FULLDISC","url":"http://seclists.org/fulldisclosure/2014/Dec/23"},{"name":"56888","refsource":"SECUNIA","url":"http://secunia.com/advisories/56888"},{"name":"FEDORA-2014-2083","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html"},{"name":"openSUSE-SU-2014:0419","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html"},{"name":"mozilla-nss-cve20141490-code-exec(90885)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/90885"},{"name":"http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html"},{"name":"FEDORA-2014-2041","refsource":"FEDORA","url":"http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html"},{"name":"SUSE-SU-2014:0248","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html"},{"name":"openSUSE-SU-2014:0213","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html"},{"name":"USN-2102-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-2102-1"},{"name":"56767","refsource":"SECUNIA","url":"http://secunia.com/advisories/56767"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=930857","refsource":"CONFIRM","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=930857"},{"name":"56706","refsource":"SECUNIA","url":"http://secunia.com/advisories/56706"}]}}}},"cveMetadata":{"assignerOrgId":"f16b083a-5664-49f3-a51e-8d479e5ed7fe","assignerShortName":"mozilla","cveId":"CVE-2014-1490","datePublished":"2014-02-06T02:00:00.000Z","dateReserved":"2014-01-16T00:00:00.000Z","dateUpdated":"2024-08-06T09:42:36.290Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-02-06 05:44:25","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-362","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionEndExcluding":"24.3","matchCriteriaId":"560AF297-E823-4299-8EF1-6BC886589A9D"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionEndExcluding":"27.0","matchCriteriaId":"86B3B84A-9D1F-4863-987C-5C958B05C523"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:*","versionEndExcluding":"3.15.4","matchCriteriaId":"ACA8EEC7-FACD-41E8-AF9F-F8DB0D477D8C"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*","versionEndExcluding":"2.24","matchCriteriaId":"328319A6-42EE-408E-91A8-87156C17AE46"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*","versionEndExcluding":"24.3.0","matchCriteriaId":"C4295262-F0E0-4E6B-A01C-C7BF51CB011E"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:enterprise_manager_ops_center:*:*:*:*:*:*:*:*","versionEndExcluding":"12.1.4","matchCriteriaId":"A70BB445-EF2B-4C9D-8502-FDD6A19F8C30"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:enterprise_manager_ops_center:12.2.0:*:*:*:*:*:*:*","matchCriteriaId":"4725EA61-9BAB-4E72-9F92-ADE4624439CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:enterprise_manager_ops_center:12.2.1:*:*:*:*:*:*:*","matchCriteriaId":"D0879FB1-58E2-4EC4-8111-044642E046BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.0:*:*:*:*:*:*:*","matchCriteriaId":"C7CF2929-4CBC-4B56-87AE-F45F53BD8DD6"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:vm_server:3.2:*:*:*:*:*:x86:*","matchCriteriaId":"FC9E8528-0FB8-4BF0-A9EF-6CC84A2631A1"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*","matchCriteriaId":"5991814D-CA77-4C25-90D2-DB542B17E0AD"},{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*","matchCriteriaId":"FF47C9F0-D8DA-4B55-89EB-9B2C9383ADB9"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*","matchCriteriaId":"DE554781-1EB9-446E-911F-6C11970C47F4"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*","matchCriteriaId":"DFBF430B-0832-44B0-AA0E-BA9E467F7668"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*","matchCriteriaId":"A10BC294-9196-425F-9FB0-B1625465B47F"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*","matchCriteriaId":"3ED68ADD-BBDA-4485-BC76-58F011D72311"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:*:*:*","matchCriteriaId":"8B072472-B463-4647-885D-E40B0115C810"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:*","matchCriteriaId":"2470C6E8-2024-4CF5-9982-CFF50E88EAE9"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp3:*:*:*:*:*:*","matchCriteriaId":"2F7F8866-DEAD-44D1-AB10-21EE611AA026"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*","matchCriteriaId":"16F59A04-14CF-49E2-9973-645477EA09DA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*","matchCriteriaId":"8D305F7A-D159-4716-AB26-5E38BB5CD991"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*","matchCriteriaId":"E2076871-2E80-4605-A470-A41C1A8EC7EE"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*","matchCriteriaId":"7F61F047-129C-41A6-8A27-FFCBB8563E91"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"1490","Ordinal":"1","Title":"CVE-2014-1490","CVE":"CVE-2014-1490","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"1490","Ordinal":"1","NoteData":"Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.","Type":"Description","Title":"CVE-2014-1490"},{"CveYear":"2014","CveId":"1490","Ordinal":"2","NoteData":"2014-02-05","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"1490","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}