Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted WebGL content constructed with the Cesium JavaScript library.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:04
Type | Values Removed | Values Added |
---|---|---|
References | () http://linux.oracle.com/errata/ELSA-2014-0918.html - | |
References | () http://secunia.com/advisories/59591 - | |
References | () http://secunia.com/advisories/59719 - | |
References | () http://secunia.com/advisories/59760 - | |
References | () http://secunia.com/advisories/60083 - | |
References | () http://secunia.com/advisories/60306 - | |
References | () http://secunia.com/advisories/60486 - | |
References | () http://secunia.com/advisories/60621 - | |
References | () http://secunia.com/advisories/60628 - | |
References | () http://www.debian.org/security/2014/dsa-2986 - | |
References | () http://www.debian.org/security/2014/dsa-2996 - | |
References | () http://www.mozilla.org/security/announce/2014/mfsa2014-62.html - Vendor Advisory | |
References | () http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html - | |
References | () http://www.securityfocus.com/bid/68822 - | |
References | () http://www.securitytracker.com/id/1030619 - | |
References | () http://www.securitytracker.com/id/1030620 - | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=1028891 - | |
References | () https://security.gentoo.org/glsa/201504-01 - |
21 Oct 2024, 13:55
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:mozilla:firefox:24.0:*:*:*:*:*:*:* |
21 Oct 2024, 13:11
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:mozilla:firefox_esr:24.1.1:*:*:*:*:*:*:* |
cpe:2.3:a:mozilla:firefox:24.1.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:24.1.0:*:*:*:*:*:*:* |
Information
Published : 2014-07-23 11:12
Updated : 2024-11-21 02:04
NVD link : CVE-2014-1556
Mitre link : CVE-2014-1556
CVE.ORG link : CVE-2014-1556
JSON object : View
Products Affected
mozilla
- firefox
- thunderbird
- firefox_esr
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')