CVE-2014-1564 describes an information disclosure vulnerability in Mozilla Firefox, Firefox ESR, and Thunderbird versions prior to 32.0, 31.1, and 31.1 respectively. This flaw stems from improper memory initialization during GIF rendering, allowing remote attackers to extract sensitive process memory data. The vulnerability has a CVSS score of 4.3 (medium severity), indicating a network-based attack with medium complexity, requiring no authentication, and primarily impacting confidentiality. While not on the KEV catalog and with no Metasploit or Nuclei exploits, an ExploitDB entry exists, and it has garnered limited community discussion and media coverage, suggesting it is not actively exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.4CPE matchmatch criteria | cpe:2.3:o:opensuse:evergreen:11.4:*:*:*:*:*:*:* | ||
12.3CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
<= 31.1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
30.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:30.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.