CVE-2014-1555
Use-after-free vulnerability in the nsDocLoader::OnProgress function in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allows remote attackers to execute arbitrary code via vectors that trigger a FireOnStateChange event.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0336 (3.4%)
Percentile: 87.4%
EPSS: 2026-05-06
Affects
mozilla:firefoxmozilla:firefox_esrmozilla:thunderbirdTechnical description
Use-after-free vulnerability in the nsDocLoader::OnProgress function in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allows remote attackers to execute arbitrary code via vectors that trigger a FireOnStateChange event.
Published: 7/23/2014, 11:12:43 AM
Last modified: 5/6/2026, 10:30:45 PM