Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-1564
Description:Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that interacts with a CANVAS element associated with a malformed GIF image.
Test IDs: 1.3.6.1.4.1.25623.1.2.1.2014.69  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-1564
BugTraq ID: 69525
http://www.securityfocus.com/bid/69525
Bugtraq: 20140904 Uninit memory disclosure via truncated images in Firefox (Google Search)
http://www.securityfocus.com/archive/1/533357/100/0/threaded
http://seclists.org/fulldisclosure/2014/Sep/18
https://security.gentoo.org/glsa/201504-01
http://packetstormsecurity.com/files/128132/Mozilla-Firefox-Secret-Leak.html
http://www.securitytracker.com/id/1030793
http://www.securitytracker.com/id/1030794
http://secunia.com/advisories/60148
http://secunia.com/advisories/61114
SuSE Security Announcement: openSUSE-SU-2014:1098 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00003.html
SuSE Security Announcement: openSUSE-SU-2014:1099 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-09/msg00011.html
SuSE Security Announcement: openSUSE-SU-2015:0138 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00024.html
SuSE Security Announcement: openSUSE-SU-2015:1266 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html




© 1998-2025 E-Soft Inc. All rights reserved.