CVE-2014-1540
Use-after-free vulnerability in the nsEventListenerManager::CompileEventHandlerInternal function in the Event Listener Manager in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted web content.
Ver en NVDSeveridad
N/A
EPSS
Probabilidad de explotación (próx. 30 días): 0.0101 (1.0%)
Percentil: 77.2%
EPSS: 2026-05-06
Afecta
mozilla:firefoxDescripción técnica
Use-after-free vulnerability in the nsEventListenerManager::CompileEventHandlerInternal function in the Event Listener Manager in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted web content.
Publicada: 11/6/2014, 10:57:17
Última modificación: 6/5/2026, 22:30:45
Referencias
- http://lists.opensuse.org/opensuse-updates/2014-06/msg00040.html
- http://lists.opensuse.org/opensuse-updates/2014-07/msg00001.html
- http://secunia.com/advisories/59052
- http://secunia.com/advisories/59171
- http://secunia.com/advisories/59387
- http://secunia.com/advisories/59486
- http://secunia.com/advisories/59866
- http://www.mozilla.org/security/announce/2014/mfsa2014-51.html