← Back

CVE-2014-1498

nvd nist
Published: Mar 19, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger generation of a key that supports the Elliptic Curve ec-dual-use algorithm.

Affected (10)

Show all products
3 products
Linux Enterprise Desktop
Linux Enterprise Server
1 product
Solaris
1 product
Opensuse
Opensuse
2 products
Seamonkey
Firefox
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Version 11 sp3
Suse
Version 11 sp3
Version 11 sp3
Version 11 sp3
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.3
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 13.1
Opensuse Project
Version 11.4
Version 12.3
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.25
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 28.0

References (16)

Source: security@mozilla.org
Mailing ListThird Party Advisory
Source: security@mozilla.org
Mailing ListThird Party Advisory
Source: security@mozilla.org
Mailing ListThird Party Advisory
Source: security@mozilla.org
Mailing ListThird Party Advisory
Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Mailing ListThird Party Advisory
Source: security@mozilla.org
Issue TrackingVendor Advisory
Source: security@mozilla.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.