10
CVSSv2

CVE-2014-1528

Published: 30/04/2014 Updated: 30/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote malicious users to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by painting on a CANVAS element.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 12.10

canonical ubuntu linux 14.04

canonical ubuntu linux 13.10

canonical ubuntu linux 12.04

opensuse opensuse 13.1

opensuse project opensuse 12.3

oracle solaris 11.3

mozilla firefox 28.0

mozilla seamonkey 2.25

fedoraproject fedora 19

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2014-41 Out-of-bounds write in Cairo Announced April 29, 2014 Reporter Jukka Jylänki Impact High Products Firefox, SeaMonkey Fixed in Firefox ...
The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 280 and SeaMonkey 225 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by painting on a CANVAS element ...