The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CCanonical Ubuntu
OSCanonical12.0414.0414.1015.04Debian
OSDebian7.08.0Mozilla Firefox
APPMozilla31.031.1.031.1.131.3.031.5.131.5.231.5.338.0≤ 38.1.0Mozilla Firefox Esr
APPMozilla31.131.231.331.431.531.6.031.7.0Mozilla Thunderbird
APPMozilla≤ 38.0.1Oracle Solaris
OSOracle11.3SUSE Linux Enterprise Desktop
OSSuse12SUSE Linux Enterprise Server
OSSuse11SUSE Linux Enterprise Software Development Kit
OSSuse12SUSE Linux Enterprise Server
OSSuse12
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same product
GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2025-49113CRITICAL9.9⚠ KEVPL ✓same product
RCE przez deserializację PHP w Roundcube Webmail (parametr _from)
CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓same product
Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)
CVE-2025-24201CRITICAL10.0⚠ KEVPL ✓same product
Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki