CVE-2014-1545

Mozilla Netscape Portable Runtime (NSPR) before 4.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via vectors involving the sprintf and console functions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
Affected Products (NVD)
VendorProductVersion
mozillanetscape_portable_runtime
𝑥
≤ 4.10.5
mozillanetscape_portable_runtime
4.1.1
mozillanetscape_portable_runtime
4.1.2
mozillanetscape_portable_runtime
4.2
mozillanetscape_portable_runtime
4.2.2
mozillanetscape_portable_runtime
4.3
mozillanetscape_portable_runtime
4.4.1
mozillanetscape_portable_runtime
4.5.1
mozillanetscape_portable_runtime
4.6
mozillanetscape_portable_runtime
4.6.1
mozillanetscape_portable_runtime
4.6.2
mozillanetscape_portable_runtime
4.6.3
mozillanetscape_portable_runtime
4.6.4
mozillanetscape_portable_runtime
4.6.5
mozillanetscape_portable_runtime
4.6.6
mozillanetscape_portable_runtime
4.6.7
mozillanetscape_portable_runtime
4.6.8
mozillanetscape_portable_runtime
4.7
mozillanetscape_portable_runtime
4.7.1
mozillanetscape_portable_runtime
4.7.2
mozillanetscape_portable_runtime
4.7.3
mozillanetscape_portable_runtime
4.7.4
mozillanetscape_portable_runtime
4.7.5
mozillanetscape_portable_runtime
4.7.6
mozillanetscape_portable_runtime
4.8
mozillanetscape_portable_runtime
4.8.2
mozillanetscape_portable_runtime
4.8.3
mozillanetscape_portable_runtime
4.8.4
mozillanetscape_portable_runtime
4.8.5
mozillanetscape_portable_runtime
4.8.6
mozillanetscape_portable_runtime
4.8.7
mozillanetscape_portable_runtime
4.8.8
mozillanetscape_portable_runtime
4.8.9
mozillanetscape_portable_runtime
4.9
mozillanetscape_portable_runtime
4.9.1
mozillanetscape_portable_runtime
4.9.2
mozillanetscape_portable_runtime
4.9.3
mozillanetscape_portable_runtime
4.9.4
mozillanetscape_portable_runtime
4.9.5
mozillanetscape_portable_runtime
4.9.6
mozillanetscape_portable_runtime
4.10
mozillanetscape_portable_runtime
4.10.1
mozillanetscape_portable_runtime
4.10.2
mozillanetscape_portable_runtime
4.10.3
mozillanetscape_portable_runtime
4.10.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nspr
bookworm
2:4.35-1
fixed
bullseye
2:4.29-1
fixed
sid
2:4.35-1.1
fixed
trixie
2:4.35-1.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nspr
lucid
ignored
precise
Fixed 4.9.5-0ubuntu0.12.04.3
released
saucy
Fixed 2:4.9.5-1ubuntu1.2
released
trusty
Fixed 2:4.10.2-1ubuntu1.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
MozillaFirefox
suse enterprise desktop 15
52.7.3-1.35
fixed
suse enterprise sap 15
52.7.3-1.35
fixed
suse enterprise server 15
52.7.3-1.35
fixed
MozillaFirefox-devel
suse enterprise desktop 15
52.7.3-1.35
fixed
suse enterprise sap 15
52.7.3-1.35
fixed
suse enterprise server 15
52.7.3-1.35
fixed
MozillaFirefox-translations-common
suse enterprise desktop 15
52.7.3-1.35
fixed
suse enterprise sap 15
52.7.3-1.35
fixed
suse enterprise server 15
52.7.3-1.35
fixed
MozillaFirefox-translations-other
suse enterprise desktop 15
52.7.3-1.35
fixed
suse enterprise sap 15
52.7.3-1.35
fixed
suse enterprise server 15
52.7.3-1.35
fixed
MozillaThunderbird
suse enterprise desktop 15
52.8-1.2
fixed
suse enterprise desktop 15 SP1
60.6.1-3.28.1
fixed
suse enterprise sap 15
52.8-1.2
fixed
suse enterprise sap 15 SP1
60.6.1-3.28.1
fixed
suse enterprise server 15
52.8-1.2
fixed
suse enterprise server 15 SP1
60.6.1-3.28.1
fixed
suse enterprise workstation 15
52.8-1.2
fixed
suse enterprise workstation 15 SP1
60.6.1-3.28.1
fixed
MozillaThunderbird-devel
suse enterprise desktop 15
52.8-1.2
fixed
suse enterprise sap 15
52.8-1.2
fixed
suse enterprise server 15
52.8-1.2
fixed
suse enterprise workstation 15
52.8-1.2
fixed
MozillaThunderbird-translations-common
suse enterprise desktop 15
52.8-1.2
fixed
suse enterprise desktop 15 SP1
60.6.1-3.28.1
fixed
suse enterprise sap 15
52.8-1.2
fixed
suse enterprise sap 15 SP1
60.6.1-3.28.1
fixed
suse enterprise server 15
52.8-1.2
fixed
suse enterprise server 15 SP1
60.6.1-3.28.1
fixed
suse enterprise workstation 15
52.8-1.2
fixed
suse enterprise workstation 15 SP1
60.6.1-3.28.1
fixed
MozillaThunderbird-translations-other
suse enterprise desktop 15
52.8-1.2
fixed
suse enterprise desktop 15 SP1
60.6.1-3.28.1
fixed
suse enterprise sap 15
52.8-1.2
fixed
suse enterprise sap 15 SP1
60.6.1-3.28.1
fixed
suse enterprise server 15
52.8-1.2
fixed
suse enterprise server 15 SP1
60.6.1-3.28.1
fixed
suse enterprise workstation 15
52.8-1.2
fixed
suse enterprise workstation 15 SP1
60.6.1-3.28.1
fixed
mozilla-nspr
suse enterprise desktop 15
4.19-1.11
fixed
suse enterprise desktop 15 SP1
4.20-3.3.2
fixed
suse enterprise sap 12 SP5
4.21-19.9.1
fixed
suse enterprise sap 15
4.19-1.11
fixed
suse enterprise sap 15 SP1
4.20-3.3.2
fixed
suse enterprise server 12 SP3
4.13.1-18.1
fixed
suse enterprise server 12 SP4
4.13.1-18.1
fixed
suse enterprise server 12 SP5
4.21-19.9.1
fixed
suse enterprise server 15
4.19-1.11
fixed
suse enterprise server 15 SP1
4.20-3.3.2
fixed
mozilla-nspr-32bit
suse enterprise desktop 15
4.19-1.11
fixed
suse enterprise desktop 15 SP1
4.20-3.3.2
fixed
suse enterprise sap 12 SP5
4.21-19.9.1
fixed
suse enterprise sap 15
4.19-1.11
fixed
suse enterprise sap 15 SP1
4.20-3.3.2
fixed
suse enterprise server 12 SP3
4.13.1-18.1
fixed
suse enterprise server 12 SP4
4.13.1-18.1
fixed
suse enterprise server 12 SP5
4.21-19.9.1
fixed
suse enterprise server 15
4.19-1.11
fixed
suse enterprise server 15 SP1
4.20-3.3.2
fixed
mozilla-nspr-devel
suse enterprise desktop 15
4.19-1.11
fixed
suse enterprise desktop 15 SP1
4.20-3.3.2
fixed
suse enterprise sap 15
4.19-1.11
fixed
suse enterprise sap 15 SP1
4.20-3.3.2
fixed
suse enterprise server 15
4.19-1.11
fixed
suse enterprise server 15 SP1
4.20-3.3.2
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
nspr
RHEL 6
0:4.10.6-1.el6_5
fixed
RHEL 7
0:4.10.6-3.el7
fixed
nspr-devel
RHEL 6
0:4.10.6-1.el6_5
fixed
RHEL 7
0:4.10.6-3.el7
fixed
nss
RHEL 6
0:3.16.1-4.el6_5
fixed
RHEL 7
0:3.16.2.3-5.el7
fixed
nss-devel
RHEL 6
0:3.16.1-4.el6_5
fixed
RHEL 7
0:3.16.2.3-5.el7
fixed
nss-pkcs11-devel
RHEL 6
0:3.16.1-4.el6_5
fixed
RHEL 7
0:3.16.2.3-5.el7
fixed
nss-softokn
RHEL 7
0:3.16.2.3-9.el7
fixed
nss-softokn-devel
RHEL 7
0:3.16.2.3-9.el7
fixed
nss-softokn-freebl
RHEL 7
0:3.16.2.3-9.el7
fixed
nss-softokn-freebl-devel
RHEL 7
0:3.16.2.3-9.el7
fixed
nss-sysinit
RHEL 6
0:3.16.1-4.el6_5
fixed
RHEL 7
0:3.16.2.3-5.el7
fixed
nss-tools
RHEL 6
0:3.16.1-4.el6_5
fixed
RHEL 7
0:3.16.2.3-5.el7
fixed
nss-util
RHEL 6
0:3.16.1-1.el6_5
fixed
RHEL 7
0:3.16.2.3-2.el7
fixed
nss-util-devel
RHEL 6
0:3.16.1-1.el6_5
fixed
RHEL 7
0:3.16.2.3-2.el7
fixed
References