Use-After-Free Vulnerability in Mozilla Firefox and Thunderbird
CVE-2014-1563

Currently unrated

Key Information:

Vendor

Opensuse

Vendor
CVE Published:
3 September 2014

What is CVE-2014-1563?

This vulnerability exists in the mozilla::DOMSVGLength::GetTearOff function within Mozilla Firefox and Thunderbird versions prior to specified updates. It enables remote attackers to execute arbitrary code or disrupt service through heap memory corruption by crafting SVG animations that engage in improper cycle collection interactions with the DOM. This manipulation can lead to serious security breaches, including unauthorized access to system resources.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.