Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-1564


Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that interacts with a CANVAS element associated with a malformed GIF image.


Published

2014-09-03T10:55:06.637

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-824

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System opensuse evergreen 11.4 Yes
Operating System opensuse opensuse 12.3 Yes
Operating System opensuse opensuse 13.1 Yes
Application mozilla firefox ≤ 31.1.0 Yes
Application mozilla firefox 30.0 Yes
Application mozilla firefox 31.0 Yes
Application mozilla thunderbird 31.0 Yes

References