CVE-2014-1523 describes a heap-based buffer overflow in the read_u32 function within Mozilla Firefox, Thunderbird, and SeaMonkey, affecting versions prior to Firefox 29.0, Firefox ESR 24.5, Thunderbird 24.5, and SeaMonkey 2.26. This vulnerability, triggered by a crafted JPEG image, can lead to a denial of service through an out-of-bounds read and application crash. With a CVSS score of 6.5 (Medium), it requires user interaction (UI:R) but has low attack complexity (AC:L) and no authentication (PR:N), primarily impacting availability (A:H). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting a low current threat profile.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 29.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
>= 24.0, < 24.5CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 2.26CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* | ||
< 24.5CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
19CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.