[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Mozilla Products: Use-after-free during DOM interactions with SVG - CVE-2014-1563 (Mac OS X)

ID: oval:org.secpod.oval:def:21041Date: (C)2014-09-10   (M)2023-12-07
Class: VULNERABILITYFamily: macos




Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG animation with DOM interaction that triggers incorrect cycle collection.

Platform:
Apple Mac OS 14
Apple Mac OS 13
Apple Mac OS 12
Apple Mac OS 11
Apple Mac OS X 10.15
Apple Mac OS X 10.14
Apple Mac OS X 10.13
Apple Mac OS X 10.11
Apple Mac OS X 10.12
Product:
Mozilla Thunderbird
Mozilla Firefox ESR
Mozilla Firefox
Reference:
CVE-2014-1563
CVE    1
CVE-2014-1563
CPE    8
cpe:/a:mozilla:firefox_esr
cpe:/a:mozilla:firefox:30.0
cpe:/a:mozilla:thunderbird
cpe:/a:mozilla:firefox:31.0
...

© SecPod Technologies