cbcvebase.
CVE-2014-1502
published 2014-03-19

CVE-2014-1502: The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote…

PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.15%
63.2th percentile
The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.

Affected

9 ranges
VendorProductVersion rangeFixed in
mozillafirefox< 28.028.0
mozillaseamonkey< 2.252.25
opensuseopensuse
opensuse_projectopensuse
opensuse_projectopensuse
oraclesolaris
suselinux_enterprise_desktop
suselinux_enterprise_server
suselinux_enterprise_software_development_kit

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_ubuntu9.8CRITICAL
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.