Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-1496


Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.


Published

2014-03-19T10:55:06.303

Last Modified

2025-11-25T17:50:16.803

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

3.4

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mozilla firefox < 28.0 Yes
Application mozilla firefox < 24.4 Yes
Application mozilla seamonkey < 2.25 Yes
Application mozilla thunderbird < 24.4 Yes
Application suse suse_linux_enterprise_software_development_kit 11.0 Yes
Operating System suse suse_linux_enterprise_desktop 11 Yes
Operating System suse suse_linux_enterprise_server 11 Yes
Operating System suse suse_linux_enterprise_server 11 Yes

References