Skip to content
CVSS 9.8 · CRITICAL

CVE-2014-1493

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

Ver en NVD

Severidad

Puntaje: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-119

EPSS

Probabilidad de explotación (próx. 30 días): 0.0147 (1.5%)
Percentil: 81.0%
EPSS: 2026-05-06

Afecta

mozilla:firefoxmozilla:seamonkeymozilla:thunderbirdcanonical:ubuntu_linuxdebian:debian_linuxredhat:enterprise_linux_desktopredhat:enterprise_linux_eusredhat:enterprise_linux_serverredhat:enterprise_linux_server_ausredhat:enterprise_linux_server_eusredhat:enterprise_linux_server_tusredhat:enterprise_linux_workstationsuse:suse_linux_enterprise_software_development_kitopensuse:opensusesuse:suse_linux_enterprise_desktopsuse:suse_linux_enterprise_server

Descripción técnica

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

Publicada: 19/3/2014, 10:55:06
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo