CVE-2014-1578 PUBLISHED

The get_tile function in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly execute arbitrary code via WebM frames with invalid tile sizes that are improperly handled in buffering operations during video playback.

EPSS 1.64% · 81.8th percentile

Risk Scores

EPSS Score
1.64%
81.8th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSthunderbird1:31.1.2+build1-0ubuntu0.14.04.1, 0, 1:24.0+build1-0ubuntu1
Ubuntu:14.04:LTSfirefox0, 24.0+build1-0ubuntu1, 25.0+build3-0ubuntu0.13.10.1

Timeline

References

Open in Interactive Console →