Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted WebGL content constructed with the Cesium JavaScript library.
References
Configurations
Configuration 1 (hide)
|
History
21 Oct 2024, 13:55
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:mozilla:firefox_esr:24.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:24.1.0:*:*:*:*:*:*:* |
cpe:2.3:a:mozilla:firefox:24.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:24.1.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:24.1.1:*:*:*:*:*:*:* |
Information
Published : 2014-07-23 11:12
Updated : 2024-10-21 13:55
NVD link : CVE-2014-1556
Mitre link : CVE-2014-1556
JSON object : View
Products Affected
mozilla
- thunderbird
- firefox
- firefox_esr
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')