5
CVSSv2

CVE-2014-8637

Published: 14/01/2015 Updated: 08/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Mozilla Firefox prior to 35.0 and SeaMonkey prior to 2.32 do not properly initialize memory for BMP images, which allows remote malicious users to obtain sensitive information from process memory via a crafted web page that triggers the rendering of malformed BMP data within a CANVAS element.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla seamonkey

mozilla firefox

Vendor Advisories

USN-2458-1 introduced a regression in Firefox ...
This update provides compatible packages for Firefox 35 ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2015-02 Uninitialized memory use during bitmap rendering Announced January 13, 2015 Reporter Michal Zalewski Impact High Products Firefox, SeaMonkey Fixed in ...
Mozilla Firefox before 350 and SeaMonkey before 232 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers the rendering of malformed BMP data within a CANVAS element ...