peter bassill · operator
$ cve CVE-2014-1564 JSON

CVE-2014-1564 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 5.5% (pctl 93)

Patch early

A public exploit exists.

Description

Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that interacts with a CANVAS element associated with a malformed GIF image.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS5.47% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-824
On CISA KEVno
Public exploityes
Published2014-09-03
Last modified2026-06-17

Affected (4)

VendorProduct
mozillafirefox
mozillathunderbird
opensuseevergreen
opensuseopensuse

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD