CVE-2014-1525: Canonical Ubuntu Linux
High severity, CVSS 9.3. EPSS: 4.4% chance of exploitation in the next 30 days.
The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection for Text Track Manager variables, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and heap memory corruption) via a crafted VIDEO element in an HTML document.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 12.10 only; version 13.10 only; version 14.04 only
- Fedoraproject Fedora: version 19 only
- Mozilla Firefox: before 29.0 (fixed in 29.0)
- Mozilla Seamonkey: before 2.26 (fixed in 2.26)
- Opensuse Opensuse: version 12.3 only; version 13.1 only
Published 2014-04-30. Last modified 2026-06-17.