CVE-2014-8641: Mozilla Firefox

High severity, CVSS 7.5. EPSS: 4.2% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the WebRTC implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, and SeaMonkey before 2.32 allows remote attackers to execute arbitrary code via crafted track data.

Affected products

  • Mozilla Firefox: version 31.0 only; version 31.1.0 only; version 31.1.1 only; version 31.3.0 only; up to and including 34.0.5
  • Mozilla Firefox ESR: version 31.2 only
  • Mozilla Seamonkey: up to and including 2.31

Published 2015-01-14. Last modified 2026-06-17.