mozilla network-security-services CVE-2014-1544 vulnerability in Mozilla Products
Published on July 23, 2014

product logo product logo product logo
Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.

Vendor Advisory Vendor Advisory Vendor Advisory NVD


Products Associated with CVE-2014-1544

Want to know whenever a new CVE is published for Mozilla products? stack.watch will email you.

 
 
 
 

Exploit Probability

EPSS
3.25%
Percentile
86.91%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.