CVE-2014-1512 is a critical use-after-free vulnerability in the TypeObject class of the JavaScript engine affecting Mozilla Firefox before version 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25. This flaw allows remote attackers to execute arbitrary code by manipulating memory consumption during garbage collection, specifically through improper handling of BumpChunk objects. With a CVSS score of 10.0, it represents a severe threat due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, there is evidence of exploitation at Pwn2Own, and it has garnered significant community discussion and media coverage, indicating its importance despite the lack of public exploit intelligence like Metasploit or ExploitDB modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 28.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
>= 24.0, < 24.4CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 2.25CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* | ||
< 24.4CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.