CVE-2014-1556
published 2014-07-23CVE-2014-1556: Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted WebGL…
PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.76%
88.8th percentile
Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted WebGL content constructed with the Cesium JavaScript library.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 30.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 31.0+build1-0ubuntu0.14.04.1 | 31.0+build1-0ubuntu0.14.04.1 |
| mozilla | firefox_esr | — | — |
| mozilla | firefox_esr | — | — |
| mozilla | firefox_esr | — | — |
| mozilla | firefox_esr | — | — |
| mozilla | firefox_esr | — | — |
| mozilla | thunderbird | <= 24.6 | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | — | — |
| mozilla | thunderbird | >= 0 < 1:31.0+build1-0ubuntu0.14.04.1 | 1:31.0+build1-0ubuntu0.14.04.1 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-34vf-569h-6rj4: Mozilla Firefox before 31
ghsa_unreviewed·2022-05-17
CVE-2014-1556 [HIGH] CWE-94 GHSA-34vf-569h-6rj4: Mozilla Firefox before 31
Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted WebGL content constructed with the Cesium JavaScript library.
OSV
firefox vulnerabilities
osv·2014-07-22·CVSS 10.0
[CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Christian Holler, David Keeler, Byron Campen, Gary Kwong, Jesse Ruderman,
Andrew McCreight, Alon Zakai, Bobby Holley, Jonathan Watt, Shu-yu Guo,
Steve Fink, Terrence Cole, Gijs Kruitbosch and Cătălin Badea discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-1547, CVE-2014-1548)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. An attacker could potentially exploit this to cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking Fi
OSV
thunderbird vulnerabilities
osv·2014-07-22·CVSS 10.0
CVE-2014-1547 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler, David Keeler and Byron Campen discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message with scripting enabled, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2014-1547)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. If a user had enabled scripting, an attacker could potentially
exploit this to cause a denial of service via application crash or execute
arbitrary code with the privileges of the user invoking Thunderbird.
(CVE-2014-1549)
Atte Kettunen discovered a use-after-free in WebAudio. If a user had
enabled
OSV
CVE-2014-1556: Mozilla Firefox before 31
osv·2014-07-22·CVSS 9.3
CVE-2014-1556 [CRITICAL] CVE-2014-1556: Mozilla Firefox before 31
Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted WebGL content constructed with the Cesium JavaScript library.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2014-07-22·CVSS 10.0
CVE-2014-1547 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Christian Holler, David Keeler and Byron Campen discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message with scripting enabled, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2014-1547)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. If a user had enabled scripting, an attacker could potentially
exploit this to cause a denial of service via application crash or execute
arbitrary code with the privileges of the user invoking Thunderbird.
(CVE-2014-1549)
Atte Kett
Red Hat
Mozilla: Exploitable WebGL crash with Cesium JavaScript library (MFSA 2014-62)
vendor_redhat·2014-07-22·CVSS 9.3
CVE-2014-1556 [CRITICAL] Mozilla: Exploitable WebGL crash with Cesium JavaScript library (MFSA 2014-62)
Mozilla: Exploitable WebGL crash with Cesium JavaScript library (MFSA 2014-62)
Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted WebGL content constructed with the Cesium JavaScript library.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2014-07-22·CVSS 10.0
CVE-2014-1547 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Christian Holler, David Keeler, Byron Campen, Gary Kwong, Jesse Ruderman,
Andrew McCreight, Alon Zakai, Bobby Holley, Jonathan Watt, Shu-yu Guo,
Steve Fink, Terrence Cole, Gijs Kruitbosch and Cătălin Badea discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-1547, CVE-2014-1548)
Atte Kettunen discovered a buffer overflow when interacting with WebAudio
buffers. An attacker could potentially exploit this to cause
No detection rules found.
No public exploits indexed.
http://linux.oracle.com/errata/ELSA-2014-0918.htmlhttp://secunia.com/advisories/59591http://secunia.com/advisories/59719http://secunia.com/advisories/59760http://secunia.com/advisories/60083http://secunia.com/advisories/60306http://secunia.com/advisories/60486http://secunia.com/advisories/60621http://secunia.com/advisories/60628http://www.debian.org/security/2014/dsa-2986http://www.debian.org/security/2014/dsa-2996http://www.mozilla.org/security/announce/2014/mfsa2014-62.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/68822http://www.securitytracker.com/id/1030619http://www.securitytracker.com/id/1030620https://bugzilla.mozilla.org/show_bug.cgi?id=1028891https://security.gentoo.org/glsa/201504-01http://linux.oracle.com/errata/ELSA-2014-0918.htmlhttp://secunia.com/advisories/59591http://secunia.com/advisories/59719http://secunia.com/advisories/59760http://secunia.com/advisories/60083http://secunia.com/advisories/60306http://secunia.com/advisories/60486http://secunia.com/advisories/60621http://secunia.com/advisories/60628http://www.debian.org/security/2014/dsa-2986http://www.debian.org/security/2014/dsa-2996http://www.mozilla.org/security/announce/2014/mfsa2014-62.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/68822http://www.securitytracker.com/id/1030619http://www.securitytracker.com/id/1030620https://bugzilla.mozilla.org/show_bug.cgi?id=1028891https://security.gentoo.org/glsa/201504-01
2014-07-23
Published