Mozilla Firefox before 33.0 does not properly initialize memory for GIF images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers a sequence of rendering operations for truncated GIF data within a CANVAS element.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefox-esrUpgrade linux-seamonkeyUpgrade linux-thunderbirdUpgrade thunderbirdUpgrade libxulUpgrade linux-firefoxUpgrade firefoxUpgrade seamonkey | Dec 10, 2025 | Oct 14, 2014 |
| Gentoo Linux | — | Upgrade www-client/seamonkey-bin.Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey.Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox.Upgrade www-client/firefox-bin.Upgrade dev-libs/nspr. | Oct 30, 2017 | Oct 15, 2014 |
| Mfsa2014 78 | — | Upgrade to Mozilla Firefox version 33.0Upgrade to the latest version of Mozilla Firefox | Oct 16, 2014 | Oct 14, 2014 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.30.0 | Dec 11, 2014 | Oct 15, 2014 |
| Oracle Solaris | — | Upgrade web/browser/firefox to version 38.4.0-0.175.3.8.0.2.0 on Solaris 11.3Upgrade runtime/tcl-8/tcl-sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3/documentation to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | Oct 15, 2014 |
| Suse | — | Upgrade MozillaFirefoxUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-common | Dec 18, 2015 | Oct 15, 2014 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Oct 15, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub