Files
CVEs-PoC/2014/CVE-2014-1578.md
T
2024-06-18 02:51:15 +02:00

19 lines
917 B
Markdown

### [CVE-2014-1578](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1578)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
The get_tile function in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly execute arbitrary code via WebM frames with invalid tile sizes that are improperly handled in buffering operations during video playback.
### POC
#### Reference
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=1063327
#### Github
No PoCs found on GitHub currently.