The get_tile function in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly execute arbitrary code via WebM frames with invalid tile sizes that are improperly handled in buffering operations during video playback.
2014-10-15T10:55:06.770
2025-04-12T10:46:40.837
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | firefox | 31.0 | Yes |
Application | mozilla | firefox | 31.1.0 | Yes |
Application | mozilla | firefox | ≤ 32.0 | Yes |
Application | mozilla | firefox | 30.0 | Yes |
Application | mozilla | firefox | 31.0 | Yes |
Application | mozilla | firefox | 31.1.0 | Yes |
Application | mozilla | thunderbird | 31.0 | Yes |
Application | mozilla | thunderbird | 31.1.0 | Yes |