CVE-2014-8637: Mozilla Firefox

Medium severity, CVSS 5.0. EPSS: 2.2% chance of exploitation in the next 30 days.

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers the rendering of malformed BMP data within a CANVAS element.

Affected products

  • Mozilla Firefox: up to and including 34.0.5
  • Mozilla Seamonkey: up to and including 2.31

Published 2015-01-14. Last modified 2026-06-17.