Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-1512

51
FAUCET Score

CVE-2014-1512 is a critical use-after-free vulnerability in the TypeObject class of the JavaScript engine affecting Mozilla Firefox before version 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25. This flaw allows remote attackers to execute arbitrary code by manipulating memory consumption during garbage collection, specifically through improper handling of BumpChunk objects. With a CVSS score of 10.0, it represents a severe threat due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, there is evidence of exploitation at Pwn2Own, and it has garnered significant community discussion and media coverage, indicating its importance despite the lack of public exploit intelligence like Metasploit or ExploitDB modules.

Impacted Technologies

VendorProductVersion(s)CPE
< 28.0CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
>= 24.0, < 24.4CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
< 2.25CPE matchmatch criteria
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
< 24.4CPE matchmatch criteria
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

10.0HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
31.37%
Probability of exploitation in next 30 days
EPSS Percentile
98.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.3137 is in the 97th percentile among its peer group of 51,466 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: firefox-0:24.4.0-1.el5_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: thunderbird-0:24.4.0-1.el5_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: firefox-0:24.4.0-1.el6_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: thunderbird-0:24.4.0-1.el6_5
View patch
mozillavendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2014-1512Critical

Mozilla: Use-after-free in TypeObject (MFSA 2014-30)

Mar 18, 2014

References

archives.neohapsis.com / archives/bugtraq/2014-03/0145.html
Broken Link
lists.opensuse.org / opensuse-security-announce/2014-03/msg00016.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-03/msg00017.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-03/msg00022.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-04/msg00016.html
Mailing ListThird Party Advisory
rhn.redhat.com / errata/RHSA-2014-0310.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2014-0316.html
Third Party Advisory
bugzilla.mozilla.org / show_bug.cgi
ExploitIssue TrackingVendor Advisory
security.gentoo.org / glsa/201504-01
Third Party Advisory
debian.org / security/2014/dsa-2881
Third Party Advisory
debian.org / security/2014/dsa-2911
Third Party Advisory
mozilla.org / security/announce/2014/mfsa2014-30.html
Vendor Advisory
oracle.com / technetwork/topics/security/bulletinapr2016-2952098.html
Third Party Advisory
securityfocus.com / bid/66209
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2151-1
Third Party Advisory