ALT-BU-2014-2592-1
Branch sisyphus update bulletin.
Closed vulnerabilities
BDU:2015-00046
Уязвимость почтового сервера Dovecot, позволяющая удаленному злоумышленнику вызвать отказ в обслуживании
Modified: 2025-04-12
CVE-2014-3430
Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attackers to cause a denial of service (resource consumption) via an incomplete SSL/TLS handshake for an IMAP/POP3 connection.
- http://advisories.mageia.org/MGASA-2014-0223.html
- http://dovecot.org/pipermail/dovecot-news/2014-May/000273.html
- http://linux.oracle.com/errata/ELSA-2014-0790.html
- http://permalink.gmane.org/gmane.mail.imap.dovecot/77499
- http://rhn.redhat.com/errata/RHSA-2014-0790.html
- http://secunia.com/advisories/59051
- http://secunia.com/advisories/59537
- http://secunia.com/advisories/59552
- http://www.debian.org/security/2014/dsa-2954
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:113
- http://www.openwall.com/lists/oss-security/2014/05/09/4
- http://www.openwall.com/lists/oss-security/2014/05/09/8
- http://www.securityfocus.com/bid/67306
- http://www.ubuntu.com/usn/USN-2213-1
- http://advisories.mageia.org/MGASA-2014-0223.html
- http://dovecot.org/pipermail/dovecot-news/2014-May/000273.html
- http://linux.oracle.com/errata/ELSA-2014-0790.html
- http://permalink.gmane.org/gmane.mail.imap.dovecot/77499
- http://rhn.redhat.com/errata/RHSA-2014-0790.html
- http://secunia.com/advisories/59051
- http://secunia.com/advisories/59537
- http://secunia.com/advisories/59552
- http://www.debian.org/security/2014/dsa-2954
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:113
- http://www.openwall.com/lists/oss-security/2014/05/09/4
- http://www.openwall.com/lists/oss-security/2014/05/09/8
- http://www.securityfocus.com/bid/67306
- http://www.ubuntu.com/usn/USN-2213-1
Closed vulnerabilities
Modified: 2025-04-11
CVE-2013-1740
The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
- http://www.securityfocus.com/bid/64944
- http://www.ubuntu.com/usn/USN-2088-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- https://bugs.gentoo.org/show_bug.cgi?id=498172
- https://bugzilla.mozilla.org/show_bug.cgi?id=919877
- https://bugzilla.redhat.com/show_bug.cgi?id=1053725
- https://developer.mozilla.org/docs/NSS/NSS_3.15.4_release_notes
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90394
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
- http://www.securityfocus.com/bid/64944
- http://www.ubuntu.com/usn/USN-2088-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- https://bugs.gentoo.org/show_bug.cgi?id=498172
- https://bugzilla.mozilla.org/show_bug.cgi?id=919877
- https://bugzilla.redhat.com/show_bug.cgi?id=1053725
- https://developer.mozilla.org/docs/NSS/NSS_3.15.4_release_notes
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90394
Modified: 2025-04-11
CVE-2014-1490
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102876
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-12.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
- http://www.securityfocus.com/bid/65335
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=930857
- https://bugzilla.mozilla.org/show_bug.cgi?id=930874
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90885
- https://security.gentoo.org/glsa/201504-01
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102876
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-12.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
- http://www.securityfocus.com/bid/65335
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=930857
- https://bugzilla.mozilla.org/show_bug.cgi?id=930874
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90885
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1491
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.
- http://hg.mozilla.org/projects/nss/rev/12c42006aed8
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.debian.org/security/2014/dsa-2994
- http://www.mozilla.org/security/announce/2014/mfsa2014-12.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
- http://www.securityfocus.com/bid/65332
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=934545
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90886
- https://security.gentoo.org/glsa/201504-01
- http://hg.mozilla.org/projects/nss/rev/12c42006aed8
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.debian.org/security/2014/dsa-2994
- http://www.mozilla.org/security/announce/2014/mfsa2014-12.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
- http://www.securityfocus.com/bid/65332
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=934545
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90886
- https://security.gentoo.org/glsa/201504-01
Closed vulnerabilities
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
Closed vulnerabilities
BDU:2014-00234
Уязвимость браузера Firefox, позволяющая злоумышленнику получить доступ к аутентификационным данным
BDU:2014-00235
Уязвимость браузера Firefox ESR, позволяющая злоумышленнику получить доступ к аутентификационным данным
BDU:2014-00236
Уязвимость почтового клиента Thunderbird, позволяющая злоумышленнику получить доступ к аутентификационным данным
BDU:2014-00237
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику получить доступ к аутентификационным данным
BDU:2014-00238
Уязвимость браузера Firefox, позволяющая злоумышленнику вызывать непреднамеренный запуск загруженного файла
BDU:2014-00239
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику вызывать непреднамеренный запуск загруженного файла
BDU:2014-00245
Уязвимость браузера Firefox, позволяющая злоумышленнику выполнить произвольный код
BDU:2014-00246
Уязвимость в программном продукте Mozilla SeaMonkey, позволяющая злоумышленнику выполнить произвольный код
BDU:2014-00255
Уязвимость браузера Firefox, позволяющая злоумышленнику выполнить произвольный код
BDU:2014-00256
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику выполнить произвольный код
BDU:2014-00257
Уязвимость браузера Firefox, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00258
Уязвимость браузера Firefox ESR, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00259
Уязвимость почтового клиента Thunderbird позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00260
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00265
Уязвимость браузера Firefox, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00266
Уязвимость браузера Firefox ESR, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00267
Уязвимость почтового клиента Thunderbird, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00268
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00274
Уязвимость браузера Firefox, позволяющая злоумышленнику выполнить обход правил ограничения домена
BDU:2014-00275
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику выполнить обход правил ограничения домена
BDU:2014-00284
Уязвимость браузера Firefox, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00285
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00286
Уязвимость браузера Firefox, позволяющая злоумышленнику обойти ограничения на оконные объекты
BDU:2014-00287
Уязвимость браузера Firefox ESR, позволяющая злоумышленнику обойти ограничения на оконные объекты
BDU:2014-00288
Уязвимость почтового клиента Thunderbird, позволяющая злоумышленнику обойти ограничения на оконные объекты
BDU:2014-00289
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику обойти ограничения на оконные объекты
BDU:2014-00294
Уязвимость браузера Firefox, позволяющая злоумышленнику обойти ограничения
BDU:2014-00295
Уязвимость браузера Firefox ESR, позволяющая злоумышленнику обойти ограничения
BDU:2014-00296
Уязвимость почтового клиента Thunderbird, позволяющая злоумышленнику обойти ограничения
BDU:2014-00297
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику обойти ограничения
BDU:2014-00298
Уязвимость браузера Firefox, позволяющая злоумышленнику выполнить произвольный код или выполнить отказ в обслуживании
BDU:2014-00299
Уязвимость браузера Firefox ESR, позволяющая злоумышленнику выполнить произвольный код или выполнить отказ в обслуживании
BDU:2014-00300
Уязвимость почтового клиента Thunderbird, позволяющая злоумышленнику выполнить произвольный код или выполнить отказ в обслуживании
BDU:2014-00301
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику выполнить произвольный код или выполнить отказ в обслуживании
BDU:2014-00316
Уязвимость браузера Firefox, позволяющая злоумышленнику выполнить отказ в обслуживании
BDU:2014-00317
Уязвимость браузера Firefox, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00318
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику вызвать отказ в обслуживании
Modified: 2025-04-11
CVE-2014-1477
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102864
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-01.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65317
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=921470
- https://bugzilla.mozilla.org/show_bug.cgi?id=925896
- https://bugzilla.mozilla.org/show_bug.cgi?id=936808
- https://bugzilla.mozilla.org/show_bug.cgi?id=937132
- https://bugzilla.mozilla.org/show_bug.cgi?id=937697
- https://bugzilla.mozilla.org/show_bug.cgi?id=945334
- https://bugzilla.mozilla.org/show_bug.cgi?id=945939
- https://bugzilla.mozilla.org/show_bug.cgi?id=950000
- https://bugzilla.mozilla.org/show_bug.cgi?id=950438
- https://bugzilla.mozilla.org/show_bug.cgi?id=951366
- https://bugzilla.mozilla.org/show_bug.cgi?id=953114
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90899
- https://security.gentoo.org/glsa/201504-01
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102864
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-01.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65317
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=921470
- https://bugzilla.mozilla.org/show_bug.cgi?id=925896
- https://bugzilla.mozilla.org/show_bug.cgi?id=936808
- https://bugzilla.mozilla.org/show_bug.cgi?id=937132
- https://bugzilla.mozilla.org/show_bug.cgi?id=937697
- https://bugzilla.mozilla.org/show_bug.cgi?id=945334
- https://bugzilla.mozilla.org/show_bug.cgi?id=945939
- https://bugzilla.mozilla.org/show_bug.cgi?id=950000
- https://bugzilla.mozilla.org/show_bug.cgi?id=950438
- https://bugzilla.mozilla.org/show_bug.cgi?id=951366
- https://bugzilla.mozilla.org/show_bug.cgi?id=953114
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90899
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1478
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the MPostWriteBarrier class in js/src/jit/MIR.h and stack alignment in js/src/jit/AsmJS.cpp in OdinMonkey, and unknown other vectors.
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102865
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.mozilla.org/security/announce/2014/mfsa2014-01.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65324
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=867597
- https://bugzilla.mozilla.org/show_bug.cgi?id=911707
- https://bugzilla.mozilla.org/show_bug.cgi?id=911845
- https://bugzilla.mozilla.org/show_bug.cgi?id=916635
- https://bugzilla.mozilla.org/show_bug.cgi?id=922603
- https://bugzilla.mozilla.org/show_bug.cgi?id=924348
- https://bugzilla.mozilla.org/show_bug.cgi?id=925308
- https://bugzilla.mozilla.org/show_bug.cgi?id=932162
- https://bugzilla.mozilla.org/show_bug.cgi?id=938431
- https://bugzilla.mozilla.org/show_bug.cgi?id=939472
- https://bugzilla.mozilla.org/show_bug.cgi?id=942152
- https://bugzilla.mozilla.org/show_bug.cgi?id=942940
- https://bugzilla.mozilla.org/show_bug.cgi?id=944278
- https://bugzilla.mozilla.org/show_bug.cgi?id=944321
- https://bugzilla.mozilla.org/show_bug.cgi?id=944851
- https://bugzilla.mozilla.org/show_bug.cgi?id=945585
- https://bugzilla.mozilla.org/show_bug.cgi?id=946733
- https://bugzilla.mozilla.org/show_bug.cgi?id=950452
- https://bugzilla.mozilla.org/show_bug.cgi?id=953373
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90900
- https://security.gentoo.org/glsa/201504-01
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102865
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.mozilla.org/security/announce/2014/mfsa2014-01.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65324
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=867597
- https://bugzilla.mozilla.org/show_bug.cgi?id=911707
- https://bugzilla.mozilla.org/show_bug.cgi?id=911845
- https://bugzilla.mozilla.org/show_bug.cgi?id=916635
- https://bugzilla.mozilla.org/show_bug.cgi?id=922603
- https://bugzilla.mozilla.org/show_bug.cgi?id=924348
- https://bugzilla.mozilla.org/show_bug.cgi?id=925308
- https://bugzilla.mozilla.org/show_bug.cgi?id=932162
- https://bugzilla.mozilla.org/show_bug.cgi?id=938431
- https://bugzilla.mozilla.org/show_bug.cgi?id=939472
- https://bugzilla.mozilla.org/show_bug.cgi?id=942152
- https://bugzilla.mozilla.org/show_bug.cgi?id=942940
- https://bugzilla.mozilla.org/show_bug.cgi?id=944278
- https://bugzilla.mozilla.org/show_bug.cgi?id=944321
- https://bugzilla.mozilla.org/show_bug.cgi?id=944851
- https://bugzilla.mozilla.org/show_bug.cgi?id=945585
- https://bugzilla.mozilla.org/show_bug.cgi?id=946733
- https://bugzilla.mozilla.org/show_bug.cgi?id=950452
- https://bugzilla.mozilla.org/show_bug.cgi?id=953373
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90900
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1479
The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent certain cloning operations, which allows remote attackers to bypass intended restrictions on XUL content via vectors involving XBL content scopes.
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102866
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-02.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65320
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=911864
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90898
- https://security.gentoo.org/glsa/201504-01
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102866
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-02.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65320
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=911864
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90898
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1480
The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a downloaded file, via a crafted web site.
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102867
- http://secunia.com/advisories/56888
- http://www.mozilla.org/security/announce/2014/mfsa2014-03.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65331
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- https://bugzilla.mozilla.org/show_bug.cgi?id=916726
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90897
- https://security.gentoo.org/glsa/201504-01
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102867
- http://secunia.com/advisories/56888
- http://www.mozilla.org/security/announce/2014/mfsa2014-03.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65331
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- https://bugzilla.mozilla.org/show_bug.cgi?id=916726
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90897
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1481
Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across different JavaScript engines.
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102863
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-13.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65326
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=936056
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90883
- https://security.gentoo.org/glsa/201504-01
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102863
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-13.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65326
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=936056
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90883
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1482
RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as demonstrated by Goo Create.
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102868
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-04.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65328
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=943803
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90894
- https://security.gentoo.org/glsa/201504-01
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102868
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-04.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65328
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=943803
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90894
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1483
Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102869
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56888
- http://www.mozilla.org/security/announce/2014/mfsa2014-05.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65316
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=950427
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90893
- https://security.gentoo.org/glsa/201504-01
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102869
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56888
- http://www.mozilla.org/security/announce/2014/mfsa2014-05.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65316
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=950427
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90893
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1485
The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102871
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56888
- http://www.mozilla.org/security/announce/2014/mfsa2014-07.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65322
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=910139
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90891
- https://security.gentoo.org/glsa/201504-01
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102871
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56888
- http://www.mozilla.org/security/announce/2014/mfsa2014-07.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65322
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=910139
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90891
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1486
Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving unspecified Content-Type values for image data.
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102872
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-08.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65334
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=942164
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90890
- https://security.gentoo.org/glsa/201504-01
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102872
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-08.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65334
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=942164
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90890
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1487
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102873
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-09.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65330
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=947592
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90889
- https://security.gentoo.org/glsa/201504-01
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102873
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-09.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65330
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=947592
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90889
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1488
The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-thread object-passing operation in conjunction with use of asm.js.
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102875
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56888
- http://www.mozilla.org/security/announce/2014/mfsa2014-11.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65321
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=950604
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90887
- https://security.gentoo.org/glsa/201504-01
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102875
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56888
- http://www.mozilla.org/security/announce/2014/mfsa2014-11.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65321
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=950604
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90887
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1489
Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://osvdb.org/102874
- http://secunia.com/advisories/56888
- http://www.mozilla.org/security/announce/2014/mfsa2014-10.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65329
- http://www.securitytracker.com/id/1029717
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- https://bugzilla.mozilla.org/show_bug.cgi?id=959531
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90888
- https://security.gentoo.org/glsa/201504-01
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://osvdb.org/102874
- http://secunia.com/advisories/56888
- http://www.mozilla.org/security/announce/2014/mfsa2014-10.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65329
- http://www.securitytracker.com/id/1029717
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- https://bugzilla.mozilla.org/show_bug.cgi?id=959531
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90888
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1490
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102876
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-12.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
- http://www.securityfocus.com/bid/65335
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=930857
- https://bugzilla.mozilla.org/show_bug.cgi?id=930874
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90885
- https://security.gentoo.org/glsa/201504-01
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102876
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-12.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
- http://www.securityfocus.com/bid/65335
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=930857
- https://bugzilla.mozilla.org/show_bug.cgi?id=930874
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90885
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1491
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.
- http://hg.mozilla.org/projects/nss/rev/12c42006aed8
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.debian.org/security/2014/dsa-2994
- http://www.mozilla.org/security/announce/2014/mfsa2014-12.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
- http://www.securityfocus.com/bid/65332
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=934545
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90886
- https://security.gentoo.org/glsa/201504-01
- http://hg.mozilla.org/projects/nss/rev/12c42006aed8
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.debian.org/security/2014/dsa-2994
- http://www.mozilla.org/security/announce/2014/mfsa2014-12.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
- http://www.securityfocus.com/bid/65332
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=934545
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90886
- https://security.gentoo.org/glsa/201504-01
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
Package thunderbird updated to version 24.3.0-alt1 for branch sisyphus in task 113811.
Closed vulnerabilities
BDU:2014-00234
Уязвимость браузера Firefox, позволяющая злоумышленнику получить доступ к аутентификационным данным
BDU:2014-00235
Уязвимость браузера Firefox ESR, позволяющая злоумышленнику получить доступ к аутентификационным данным
BDU:2014-00236
Уязвимость почтового клиента Thunderbird, позволяющая злоумышленнику получить доступ к аутентификационным данным
BDU:2014-00237
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику получить доступ к аутентификационным данным
BDU:2014-00257
Уязвимость браузера Firefox, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00258
Уязвимость браузера Firefox ESR, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00259
Уязвимость почтового клиента Thunderbird позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00260
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00265
Уязвимость браузера Firefox, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00266
Уязвимость браузера Firefox ESR, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00267
Уязвимость почтового клиента Thunderbird, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00268
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании
BDU:2014-00286
Уязвимость браузера Firefox, позволяющая злоумышленнику обойти ограничения на оконные объекты
BDU:2014-00287
Уязвимость браузера Firefox ESR, позволяющая злоумышленнику обойти ограничения на оконные объекты
BDU:2014-00288
Уязвимость почтового клиента Thunderbird, позволяющая злоумышленнику обойти ограничения на оконные объекты
BDU:2014-00289
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику обойти ограничения на оконные объекты
BDU:2014-00294
Уязвимость браузера Firefox, позволяющая злоумышленнику обойти ограничения
BDU:2014-00295
Уязвимость браузера Firefox ESR, позволяющая злоумышленнику обойти ограничения
BDU:2014-00296
Уязвимость почтового клиента Thunderbird, позволяющая злоумышленнику обойти ограничения
BDU:2014-00297
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику обойти ограничения
BDU:2014-00298
Уязвимость браузера Firefox, позволяющая злоумышленнику выполнить произвольный код или выполнить отказ в обслуживании
BDU:2014-00299
Уязвимость браузера Firefox ESR, позволяющая злоумышленнику выполнить произвольный код или выполнить отказ в обслуживании
BDU:2014-00300
Уязвимость почтового клиента Thunderbird, позволяющая злоумышленнику выполнить произвольный код или выполнить отказ в обслуживании
BDU:2014-00301
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику выполнить произвольный код или выполнить отказ в обслуживании
Modified: 2025-04-11
CVE-2014-1477
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102864
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-01.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65317
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=921470
- https://bugzilla.mozilla.org/show_bug.cgi?id=925896
- https://bugzilla.mozilla.org/show_bug.cgi?id=936808
- https://bugzilla.mozilla.org/show_bug.cgi?id=937132
- https://bugzilla.mozilla.org/show_bug.cgi?id=937697
- https://bugzilla.mozilla.org/show_bug.cgi?id=945334
- https://bugzilla.mozilla.org/show_bug.cgi?id=945939
- https://bugzilla.mozilla.org/show_bug.cgi?id=950000
- https://bugzilla.mozilla.org/show_bug.cgi?id=950438
- https://bugzilla.mozilla.org/show_bug.cgi?id=951366
- https://bugzilla.mozilla.org/show_bug.cgi?id=953114
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90899
- https://security.gentoo.org/glsa/201504-01
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102864
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-01.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65317
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=921470
- https://bugzilla.mozilla.org/show_bug.cgi?id=925896
- https://bugzilla.mozilla.org/show_bug.cgi?id=936808
- https://bugzilla.mozilla.org/show_bug.cgi?id=937132
- https://bugzilla.mozilla.org/show_bug.cgi?id=937697
- https://bugzilla.mozilla.org/show_bug.cgi?id=945334
- https://bugzilla.mozilla.org/show_bug.cgi?id=945939
- https://bugzilla.mozilla.org/show_bug.cgi?id=950000
- https://bugzilla.mozilla.org/show_bug.cgi?id=950438
- https://bugzilla.mozilla.org/show_bug.cgi?id=951366
- https://bugzilla.mozilla.org/show_bug.cgi?id=953114
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90899
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1479
The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent certain cloning operations, which allows remote attackers to bypass intended restrictions on XUL content via vectors involving XBL content scopes.
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102866
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-02.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65320
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=911864
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90898
- https://security.gentoo.org/glsa/201504-01
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102866
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-02.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65320
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=911864
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90898
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1481
Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across different JavaScript engines.
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102863
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-13.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65326
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=936056
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90883
- https://security.gentoo.org/glsa/201504-01
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102863
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-13.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65326
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=936056
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90883
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1482
RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as demonstrated by Goo Create.
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102868
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-04.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65328
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=943803
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90894
- https://security.gentoo.org/glsa/201504-01
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102868
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-04.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65328
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=943803
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90894
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1486
Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving unspecified Content-Type values for image data.
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102872
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-08.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65334
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=942164
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90890
- https://security.gentoo.org/glsa/201504-01
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102872
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-08.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65334
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=942164
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90890
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1487
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102873
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-09.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65330
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=947592
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90889
- https://security.gentoo.org/glsa/201504-01
- http://download.novell.com/Download?buildid=VYQsgaFpQ2k
- http://download.novell.com/Download?buildid=Y2fux-JW1Qc
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102873
- http://rhn.redhat.com/errata/RHSA-2014-0132.html
- http://rhn.redhat.com/errata/RHSA-2014-0133.html
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56761
- http://secunia.com/advisories/56763
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-09.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/65330
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=947592
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90889
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1490
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102876
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-12.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
- http://www.securityfocus.com/bid/65335
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=930857
- https://bugzilla.mozilla.org/show_bug.cgi?id=930874
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90885
- https://security.gentoo.org/glsa/201504-01
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://osvdb.org/102876
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/56706
- http://secunia.com/advisories/56767
- http://secunia.com/advisories/56787
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.mozilla.org/security/announce/2014/mfsa2014-12.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
- http://www.securityfocus.com/bid/65335
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- https://8pecxstudios.com/?page_id=44080
- https://bugzilla.mozilla.org/show_bug.cgi?id=930857
- https://bugzilla.mozilla.org/show_bug.cgi?id=930874
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90885
- https://security.gentoo.org/glsa/201504-01
Modified: 2025-04-11
CVE-2014-1491
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.
- http://hg.mozilla.org/projects/nss/rev/12c42006aed8
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.debian.org/security/2014/dsa-2994
- http://www.mozilla.org/security/announce/2014/mfsa2014-12.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
- http://www.securityfocus.com/bid/65332
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=934545
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90886
- https://security.gentoo.org/glsa/201504-01
- http://hg.mozilla.org/projects/nss/rev/12c42006aed8
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/56858
- http://secunia.com/advisories/56888
- http://secunia.com/advisories/56922
- http://www.debian.org/security/2014/dsa-2858
- http://www.debian.org/security/2014/dsa-2994
- http://www.mozilla.org/security/announce/2014/mfsa2014-12.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
- http://www.securityfocus.com/bid/65332
- http://www.securitytracker.com/id/1029717
- http://www.securitytracker.com/id/1029720
- http://www.securitytracker.com/id/1029721
- http://www.ubuntu.com/usn/USN-2102-1
- http://www.ubuntu.com/usn/USN-2102-2
- http://www.ubuntu.com/usn/USN-2119-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=934545
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90886
- https://security.gentoo.org/glsa/201504-01
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
No data currently available.
