CVE-2014-1556Code Injection in Mozilla Firefox

CWE-94Code Injection9 documents6 sources
Severity
9.3CRITICALNVD
OSV10.0
EPSS
0.9%
top 24.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 17

Description

Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted WebGL content constructed with the Cesium JavaScript library.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages5 packages

Ubuntumozilla/firefox< 31.0+build1-0ubuntu0.14.04.1
NVDmozilla/firefox30.0+5
NVDmozilla/firefox_esr5 versions+4
Ubuntumozilla/thunderbird< 1:31.0+build1-0ubuntu0.14.04.1

🔴Vulnerability Details

4
GHSA
GHSA-34vf-569h-6rj4: Mozilla Firefox before 312022-05-17
OSV
firefox vulnerabilities2014-07-22
OSV
thunderbird vulnerabilities2014-07-22
OSV
CVE-2014-1556: Mozilla Firefox before 312014-07-22

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2014-07-22
Red Hat
Mozilla: Exploitable WebGL crash with Cesium JavaScript library (MFSA 2014-62)2014-07-22
Ubuntu
Firefox vulnerabilities2014-07-22

💬Community

1
Bugzilla
CVE-2014-1556 Mozilla: Exploitable WebGL crash with Cesium JavaScript library (MFSA 2014-62)2014-07-21