Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-1525
Description:The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection for Text Track Manager variables, which allows remote attackers to execute arbitrary code or cause a denial of service (use- after-free and heap memory corruption) via a crafted VIDEO element in an HTML document.
Test IDs: 1.3.6.1.4.1.25623.1.2.1.2014.39  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-1525
http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132437.html
https://security.gentoo.org/glsa/201504-01
http://www.securitytracker.com/id/1030163
http://www.securitytracker.com/id/1030164
http://secunia.com/advisories/59866
SuSE Security Announcement: openSUSE-SU-2014:0599 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-05/msg00010.html
SuSE Security Announcement: openSUSE-SU-2014:0629 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-05/msg00033.html
http://www.ubuntu.com/usn/USN-2185-1




© 1998-2025 E-Soft Inc. All rights reserved.