CVE-2014-1580: Mozilla Firefox
Medium severity, CVSS 5.0. EPSS: 2.3% chance of exploitation in the next 30 days.
Mozilla Firefox before 33.0 does not properly initialize memory for GIF images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers a sequence of rendering operations for truncated GIF data within a CANVAS element.
Affected products
- Mozilla Firefox: up to and including 32.0; version 30.0 only; version 31.0 only; version 31.1.0 only
Published 2014-10-15. Last modified 2026-06-17.