CVE-2014-1496: Mozilla Firefox
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
Affected products
- Mozilla Firefox: before 28.0 (fixed in 28.0); from 24.0, before 24.4 (fixed in 24.4)
- Mozilla Seamonkey: before 2.25 (fixed in 2.25)
- Mozilla Thunderbird: before 24.4 (fixed in 24.4)
- Suse Suse Linux Enterprise Desktop: version 11 only
- Suse Suse Linux Enterprise Server: version 11 only
- Suse Suse Linux Enterprise Software Development Kit: version 11.0 only
Published 2014-03-19. Last modified 2026-06-17.