Arbitrary Code Execution via Crafted Media Content in Mozilla Firefox, Firefox ESR, Thunderbird, and SeaMonkey

Arbitrary Code Execution via Crafted Media Content in Mozilla Firefox, Firefox ESR, Thunderbird, and SeaMonkey

CVE-2014-1593 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

Stack-based buffer overflow in the mozilla::FileBlockCache::Read function in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to execute arbitrary code via crafted media content.

Learn more about our Cis Benchmark Audit For Mozilla Firefox.