CVE-2014-1567

critical
Published 2014-09-03 · Modified 2026-05-06
CVSS v3
CVSS v2
9.3
VIR risk
9.3

Description

Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows remote attackers to execute arbitrary code via text that is improperly handled during the interaction between directionality resolution and layout.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@mozilla.org — http://www.mozilla.org/security/announce/2014/mfsa2014-72.html

Application impact

VendorProductVersionsFixed
mozillafirefox{"endIncluding":"31.1.0"}
mozillafirefox30.0
mozillafirefox31.0
mozillafirefox24.0
mozillafirefox24.0.1
mozillafirefox24.0.2
mozillafirefox24.1.0
mozillafirefox24.1.1
mozillafirefox_esr24.2
mozillafirefox_esr24.3
mozillafirefox_esr24.4
mozillafirefox_esr24.5
mozillafirefox_esr24.6
mozillafirefox_esr24.7
mozillathunderbird24.0
mozillathunderbird24.0.1
mozillathunderbird24.1
mozillathunderbird24.1.1
mozillathunderbird24.2
mozillathunderbird24.3
mozillathunderbird24.4
mozillathunderbird24.5
mozillathunderbird24.6
mozillathunderbird24.7
mozillathunderbird31.0

References

Verify integrity in audit chain (admin only). AS-IS.