CVE-2014-1563: Mozilla Firefox

High severity, CVSS 10.0. EPSS: 5.8% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG animation with DOM interaction that triggers incorrect cycle collection.

Affected products

  • Mozilla Firefox: up to and including 31.1.0; version 30.0 only; version 31.0 only
  • Mozilla Thunderbird: version 31.0 only
  • Opensuse Evergreen: version 11.4 only
  • Opensuse Opensuse: version 12.3 only; version 13.1 only
  • Oracle Solaris: version 11.3 only

Published 2014-09-03. Last modified 2026-06-17.