CVE-2014-1545: Mozilla Netscape Portable Runtime

High severity, CVSS 10.0. EPSS: 6.3% chance of exploitation in the next 30 days.

Mozilla Netscape Portable Runtime (NSPR) before 4.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via vectors involving the sprintf and console functions.

Affected products

  • Mozilla Netscape Portable Runtime: up to and including 4.10.5; version 4.1.1 only; version 4.1.2 only; version 4.2 only; version 4.2.2 only; version 4.3 only; …

Published 2014-06-11. Last modified 2026-06-17.