CVE-2014-1545

critical
Published 2014-06-11 · Modified 2026-05-06
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Mozilla Netscape Portable Runtime (NSPR) before 4.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via vectors involving the sprintf and console functions.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-1545

vendor Authored 2026-05-27

Vendor advisory: security@mozilla.org — http://www.mozilla.org/security/announce/2014/mfsa2014-55.html

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2:4.10.6-1
debian debianbullseyefixed2:4.10.6-1
debian debianforkyfixed2:4.10.6-1
debian debiansidfixed2:4.10.6-1
debian debiantrixiefixed2:4.10.6-1

Application impact

VendorProductVersionsFixed
mozillanetscape_portable_runtime{"endIncluding":"4.10.5"}
mozillanetscape_portable_runtime4.1.1
mozillanetscape_portable_runtime4.1.2
mozillanetscape_portable_runtime4.2
mozillanetscape_portable_runtime4.2.2
mozillanetscape_portable_runtime4.3
mozillanetscape_portable_runtime4.4.1
mozillanetscape_portable_runtime4.5.1
mozillanetscape_portable_runtime4.6
mozillanetscape_portable_runtime4.6.1
mozillanetscape_portable_runtime4.6.2
mozillanetscape_portable_runtime4.6.3
mozillanetscape_portable_runtime4.6.4
mozillanetscape_portable_runtime4.6.5
mozillanetscape_portable_runtime4.6.6
mozillanetscape_portable_runtime4.6.7
mozillanetscape_portable_runtime4.6.8
mozillanetscape_portable_runtime4.7
mozillanetscape_portable_runtime4.7.1
mozillanetscape_portable_runtime4.7.2
mozillanetscape_portable_runtime4.7.3
mozillanetscape_portable_runtime4.7.4
mozillanetscape_portable_runtime4.7.5
mozillanetscape_portable_runtime4.7.6
mozillanetscape_portable_runtime4.8
mozillanetscape_portable_runtime4.8.2
mozillanetscape_portable_runtime4.8.3
mozillanetscape_portable_runtime4.8.4
mozillanetscape_portable_runtime4.8.5
mozillanetscape_portable_runtime4.8.6
mozillanetscape_portable_runtime4.8.7
mozillanetscape_portable_runtime4.8.8
mozillanetscape_portable_runtime4.8.9
mozillanetscape_portable_runtime4.9
mozillanetscape_portable_runtime4.9.1
mozillanetscape_portable_runtime4.9.2
mozillanetscape_portable_runtime4.9.3
mozillanetscape_portable_runtime4.9.4
mozillanetscape_portable_runtime4.9.5
mozillanetscape_portable_runtime4.9.6
mozillanetscape_portable_runtime4.10
mozillanetscape_portable_runtime4.10.1
mozillanetscape_portable_runtime4.10.2
mozillanetscape_portable_runtime4.10.3
mozillanetscape_portable_runtime4.10.4

References

Verify integrity in audit chain (admin only). AS-IS.