CVE-2014-1542

Opensuse < 29.0.1 - Memory Corruption

Title source: rule
STIX 2.1

Description

Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code via vectors related to a crafted AudioBuffer channel count and sample rate.

References (14)

Core 14
Core References
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2014-06/msg00040.html
Permissions Required third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59387
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030388
Permissions Required third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59052
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2014-07/msg00001.html
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=991533
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201504-01
Permissions Required third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59866
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/67968
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2243-1
Permissions Required third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59171
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59486

Scores

EPSS 0.0472
EPSS Percentile 89.5%

Details

CWE
CWE-119
Status published
Products (4)
mozilla/firefox < 29.0.1
opensuse/opensuse 13.1
opensuse_project/opensuse 12.3
oracle/solaris 11.3
Published Jun 11, 2014
Tracked Since Feb 18, 2026