CVE-2014-1563: Mozilla Firefox
High severity, CVSS 10.0. EPSS: 5.8% chance of exploitation in the next 30 days.
Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG animation with DOM interaction that triggers incorrect cycle collection.
Affected products
- Mozilla Firefox: up to and including 31.1.0; version 30.0 only; version 31.0 only
- Mozilla Thunderbird: version 31.0 only
- Opensuse Evergreen: version 11.4 only
- Opensuse Opensuse: version 12.3 only; version 13.1 only
- Oracle Solaris: version 11.3 only
Published 2014-09-03. Last modified 2026-06-17.