CVE-2014-1543
Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API in Mozilla Firefox before 30.0 allow remote attackers to execute arbitrary code by using non-contiguous axes with a (1) physical or (2) virtual Gamepad device.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0340 (3.4%)
Percentile: 87.5%
EPSS: 2026-05-06
Affects
mozilla:firefoxTechnical description
Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API in Mozilla Firefox before 30.0 allow remote attackers to execute arbitrary code by using non-contiguous axes with a (1) physical or (2) virtual Gamepad device.
Published: 6/11/2014, 10:57:18 AM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://lists.opensuse.org/opensuse-updates/2014-06/msg00040.html
- http://lists.opensuse.org/opensuse-updates/2014-07/msg00001.html
- http://secunia.com/advisories/59171
- http://secunia.com/advisories/59387
- http://secunia.com/advisories/59486
- http://secunia.com/advisories/59866
- http://www.mozilla.org/security/announce/2014/mfsa2014-54.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html