CVE-2014-1563
03.09.2014, 10:55
Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG animation with DOM interaction that triggers incorrect cycle collection.Enginsight
Vendor | Product | Version |
---|---|---|
opensuse | evergreen | 11.4 |
opensuse | opensuse | 12.3 |
opensuse | opensuse | 13.1 |
oracle | solaris | 11.3 |
mozilla | firefox | 𝑥 ≤ 31.1.0 |
mozilla | firefox | 30.0 |
mozilla | firefox | 31.0 |
mozilla | thunderbird | 31.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References