CVE-2014-1564

CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 2.55 % (90th)
2.55% Progress
Affected Products 5
Advisories 3

Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that interacts with a CANVAS element associated with a malformed GIF image.

Weaknesses
CWE-824
Access of Uninitialized Pointer
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2014-09-03 10:55:06
(10 years ago)
Updated Date
2018-10-30 16:27:34
(5 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Opensuse Evergreen 11.4 cpe:2.3:o:opensuse:evergreen:11.4
  Opensuse 12.3 cpe:2.3:o:opensuse:opensuse:12.3
  Opensuse 13.1 cpe:2.3:o:opensuse:opensuse:13.1

Configuration #2

    CPE23 From Up To
  Mozilla Firefox 31.1.0 and prior versions cpe:2.3:a:mozilla:firefox <= 31.1.0
  Mozilla Firefox 30.0 cpe:2.3:a:mozilla:firefox:30.0
  Mozilla Firefox 31.0 cpe:2.3:a:mozilla:firefox:31.0
  Mozilla Firefox Esr 31.0 cpe:2.3:a:mozilla:firefox_esr:31.0
  Mozilla Thunderbird 31.0 cpe:2.3:a:mozilla:thunderbird:31.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...