Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted WebGL content constructed with the Cesium JavaScript library.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-07-23 04:12
Updated : 2017-01-06 18:59
NVD link : CVE-2014-1556
Mitre link : CVE-2014-1556
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
mozilla
- firefox
- firefox_esr
- thunderbird