← Back

CVE-2014-1544

nvd nist
Published: Jul 23, 2014Modified: May 6, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.

Affected (71)

4 products
Firefox
Firefox Esr
Network Security Services
Thunderbird
Configuration A
71 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Up to 30.0
Version 24.0.1
Version 24.0.2
Version 24.0
Version 24.1.0
Version 24.1.1
Mozilla
Version 24.2
Version 24.3
Version 24.4
Version 24.5
Version 24.6
Mozilla
Version 3.11.2
Version 3.11.3
Version 3.11.4
Version 3.11.5
Version 3.12.10
Version 3.12.11
Version 3.12.1
Version 3.12.2
Version 3.12.3.1
Version 3.12.3.2
Version 3.12.3
Version 3.12.4
Version 3.12.5
Version 3.12.6
Version 3.12.7
Version 3.12.8
Version 3.12.9
Version 3.12
Version 3.14.1
Version 3.14.2
Version 3.14.3
Version 3.14.4
Version 3.14.5
Version 3.14
Version 3.15.1
Version 3.15.2
Version 3.15.3.1
Version 3.15.3
Version 3.15.4
Version 3.15.5
Version 3.15
Version 3.16
Version 3.2.1
Version 3.2
Version 3.3.1
Version 3.3.2
Version 3.3
Version 3.4.1
Version 3.4.2
Version 3.4
Version 3.5
Version 3.6.1
Version 3.6
Version 3.7.1
Version 3.7.2
Version 3.7.3
Version 3.7.5
Version 3.7.7
Version 3.7
Version 3.8
Version 3.9
Mozilla
Up to 24.6
Version 24.0.1
Version 24.0
Version 24.1.1
Version 24.1
Version 24.2
Version 24.3
Version 24.4
Version 24.5

References (32)

Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.