suse · CVE-2014-1497

Quick triage

Priority: critical Published: 2021-05-30 13:18:54 UTC Updated: 2026-04-18 18:44:06 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2014-1497 severity critical: SUSE including 55 source package names (MozillaFirefox-140.2.0-160000.1.2, MozillaFirefox-24.4.0esr-0.5.5.1, …), 73 product×package rows across 14 product lines (SUSE Linux Enterprise Desktop 11 SP3, SUSE Linux Enterprise Module for Desktop Applications 15, … (14 product lines)): Fixed 73.

Description:

The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause a denial of service (out-of-bounds read and application crash), or possibly have unspecified other impact via a crafted WAV file.

cvelogic Threat Intelligence