← Vulnerability feed

Vulnerability record · CVE-2014-1568 · published 25 September 2014

CVE-2014-1568: Google chrome vulnerability

Google · Chrome

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

7.5 CVSS 2.0 High EPSS 17% · top 3.1% CWE-310 · CWE-310
7.5CVSS 2.0 base score
17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
68References
17 Jun 2026Last modified by NVD

Description

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://googlechromereleases.blogspot.com/2014/09/stable-channel-update-for-chrome-os_24.html
http://googlechromereleases.blogspot.com/2014/09/stable-channel-update_24.html
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00032.html
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00036.html
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00039.html
http://rhn.redhat.com/errata/RHSA-2014-1307.html
http://rhn.redhat.com/errata/RHSA-2014-1354.html
http://rhn.redhat.com/errata/RHSA-2014-1371.html
http://secunia.com/advisories/61540
http://secunia.com/advisories/61574
http://secunia.com/advisories/61575
http://secunia.com/advisories/61576
http://secunia.com/advisories/61583
http://www.debian.org/security/2014/dsa-3033
http://www.debian.org/security/2014/dsa-3034
http://www.debian.org/security/2014/dsa-3037
http://www.kb.cert.org/vuls/id/772676 US Government Resource
http://www.mozilla.org/security/announce/2014/mfsa2014-73.html Vendor Advisory
http://www.novell.com/support/kb/doc.php?id=7015701
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
http://www.securityfocus.com/bid/70116
http://www.ubuntu.com/usn/USN-2360-1
http://www.ubuntu.com/usn/USN-2360-2
http://www.ubuntu.com/usn/USN-2361-1
https://bugzilla.mozilla.org/show_bug.cgi?id=1064636
https://bugzilla.mozilla.org/show_bug.cgi?id=1069405 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/96194
https://security.gentoo.org/glsa/201504-01
http://googlechromereleases.blogspot.com/2014/09/stable-channel-update-for-chrome-os_24.html
http://googlechromereleases.blogspot.com/2014/09/stable-channel-update_24.html
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00032.html
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00036.html

Track CVE-2014-1568 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2019-11708Mozilla Firefox and Thunderbird sandbox escape via Prompt:Open IPC validation flawThe Prompt:Open IPC message between child and parent processes does not sufficiently vet its parameters, letting a compromised child process cause th…KEVEPSS 56%analysed9.8CVE-2025-10585Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that can lead to heap corruption when processing a crafted HTML page. It affec…KEVEPSS 5.4%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2014-0497Adobe Flash Player integer underflow allows remote code executionAdobe Flash Player contains an integer underflow (CWE-191) that allows remote attackers to execute arbitrary code via unspecified vectors. The flaw a…KEVEPSS 100%analysed9.8CVE-2010-3765Mozilla Firefox, Thunderbird and SeaMonkey memory corruption via appendChildA memory corruption flaw in Mozilla Firefox, Thunderbird and SeaMonkey arises from incorrect index tracking in nsCSSFrameConstructor::ContentAppended…KEVEPSS 83%analysed9.6CVE-2024-7971Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that lets a crafted HTML page corrupt the heap. It affects Chrome before 128.0…KEVEPSS 21%analysed9.6CVE-2024-5274Google Chrome V8 type confusion allows sandbox code executionGoogle Chrome before 125.0.6422.112 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and lea…KEVEPSS 7.5%analysed9.6CVE-2024-4947Google Chrome V8 type confusion allows sandboxed remote code executionGoogle Chrome before 125.0.6422.60 contains a type confusion flaw in the V8 JavaScript engine. A crafted HTML page can trigger the confusion and let …KEVEPSS 15%analysed

Source: NIST National Vulnerability Database (record CVE-2014-1568), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.