CVE-2014-8640 describes a denial-of-service vulnerability in the Web Audio API implementation within Mozilla Firefox (before 35.0) and SeaMonkey (before 2.32). Specifically, the mozilla::dom::AudioParamTimeline::AudioNodeInputValue function improperly handles timeline operations, allowing remote attackers to trigger an uninitialized-memory read and application crash through crafted API calls. This vulnerability has a CVSS score of 5.0, indicating a medium severity. It can be exploited remotely with low attack complexity, requiring no authentication, and its primary impact is a denial of service (availability). There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are extremely low, suggesting minimal public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 34.0.5CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
13.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* | ||
<= 2.31CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.