CVE-2014-1531: Use After Free
Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving an imgLoader object that is not properly handled during an image-resize operation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1531?
CVE-2014-1531 is classified as a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2014-1531?
To address CVE-2014-1531, update to a patched version of Mozilla Firefox, Thunderbird, or SeaMonkey, as appropriate.
Which versions are affected by CVE-2014-1531?
CVE-2014-1531 affects Mozilla Firefox versions prior to 29.0, Firefox ESR versions before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26.
Can CVE-2014-1531 cause a denial of service?
Yes, CVE-2014-1531 can lead to denial of service due to heap memory corruption.
Is CVE-2014-1531 a browser-specific vulnerability?
Yes, CVE-2014-1531 specifically affects browsers and applications developed by Mozilla.