Lucene search

K
nvd[email protected]NVD:CVE-2014-1564
HistorySep 03, 2014 - 10:55 a.m.

CVE-2014-1564

2014-09-0310:55:06
CWE-824
web.nvd.nist.gov
7

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

5.9

Confidence

Low

EPSS

0.026

Percentile

90.4%

Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that interacts with a CANVAS element associated with a malformed GIF image.

Affected configurations

Nvd
Node
opensuseevergreenMatch11.4
OR
opensuseopensuseMatch12.3
OR
opensuseopensuseMatch13.1
Node
mozillafirefoxRange31.1.0
OR
mozillafirefoxMatch30.0
OR
mozillafirefoxMatch31.0
OR
mozillafirefox_esrMatch31.0
OR
mozillathunderbirdMatch31.0
VendorProductVersionCPE
opensuseevergreen11.4cpe:2.3:o:opensuse:evergreen:11.4:*:*:*:*:*:*:*
opensuseopensuse12.3cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
opensuseopensuse13.1cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillafirefox30.0cpe:2.3:a:mozilla:firefox:30.0:*:*:*:*:*:*:*
mozillafirefox31.0cpe:2.3:a:mozilla:firefox:31.0:*:*:*:*:*:*:*
mozillafirefox_esr31.0cpe:2.3:a:mozilla:firefox_esr:31.0:*:*:*:*:*:*:*
mozillathunderbird31.0cpe:2.3:a:mozilla:thunderbird:31.0:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

5.9

Confidence

Low

EPSS

0.026

Percentile

90.4%