CVE-2014-1563
03.09.2014, 10:55
Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG animation with DOM interaction that triggers incorrect cycle collection.Enginsight
| Vendor | Product | Version |
|---|---|---|
| opensuse | evergreen | 11.4 |
| opensuse | opensuse | 12.3 |
| opensuse | opensuse | 13.1 |
| oracle | solaris | 11.3 |
| mozilla | firefox | 𝑥 ≤ 31.1.0 |
| mozilla | firefox | 30.0 |
| mozilla | firefox | 31.0 |
| mozilla | thunderbird | 31.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References