[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248430

 
 

909

 
 

195407

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-1595Date: (C)2014-12-26   (M)2023-12-22


Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, which allows local users to obtain sensitive information by reading /tmp files, as demonstrated by credential information.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.1
Exploit Score: 3.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
APPLE-SA-2015-01-27-4
http://support.apple.com/HT204244
http://www.mozilla.org/security/announce/2014/mfsa2014-90.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.reddit.com/r/netsec/comments/2ocxac/apple_coregraphics_framework_on_os_x_1010_is/
https://bugzilla.mozilla.org/show_bug.cgi?id=1092855

CPE    6
cpe:/a:mozilla:firefox_esr:31.1.1
cpe:/a:mozilla:firefox:33.0
cpe:/a:mozilla:firefox_esr:31.0
cpe:/a:mozilla:thunderbird:31.2
...
CWE    1
CWE-199
OVAL    2
oval:org.secpod.oval:def:22309
oval:org.secpod.oval:def:22308

© SecPod Technologies