SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-8640

The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web Audio API implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly restrict timeline operations, which allows remote attackers to cause a…

MEDIUM 5.0EPSS 2.39%

Does this matter?

Lower severity and a low EPSS score (2.39%). Track it; it rarely justifies an emergency change on its own.

Description

The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web Audio API implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly restrict timeline operations, which allows remote attackers to cause a denial of service (uninitialized-memory read and application crash) via crafted API calls.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
2.39% probability · 83th percentile
CISA KEV
Not listed
Weakness
CWE-362
Affected
mozilla/firefox · opensuse/opensuse · mozilla/seamonkey
Source
security@mozilla.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.