Lucene search

K
cveMozillaCVE-2014-1556
HistoryJul 23, 2014 - 11:12 a.m.

CVE-2014-1556

2014-07-2311:12:43
CWE-94
mozilla
web.nvd.nist.gov
61
cve-2014-1556
mozilla firefox
thunderbird
remote code execution
webgl
cesium javascript library

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

9.6

Confidence

High

EPSS

0.041

Percentile

92.1%

Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted WebGL content constructed with the Cesium JavaScript library.

Affected configurations

Nvd
Node
mozillafirefoxRange30.0
OR
mozillafirefox_esrMatch24.0
OR
mozillafirefox_esrMatch24.0.1
OR
mozillafirefox_esrMatch24.0.2
OR
mozillafirefox_esrMatch24.1.0
OR
mozillafirefox_esrMatch24.1.1
OR
mozillafirefox_esrMatch24.2
OR
mozillafirefox_esrMatch24.3
OR
mozillafirefox_esrMatch24.4
OR
mozillafirefox_esrMatch24.5
OR
mozillafirefox_esrMatch24.6
OR
mozillathunderbirdRange24.6
OR
mozillathunderbirdMatch24.0
OR
mozillathunderbirdMatch24.0.1
OR
mozillathunderbirdMatch24.1
OR
mozillathunderbirdMatch24.1.1
OR
mozillathunderbirdMatch24.2
OR
mozillathunderbirdMatch24.3
OR
mozillathunderbirdMatch24.4
OR
mozillathunderbirdMatch24.5
VendorProductVersionCPE
mozillathunderbird24.3cpe:/a:mozilla:thunderbird:24.3:::
mozillathunderbird24.5cpe:/a:mozilla:thunderbird:24.5:::
mozillafirefox_esr24.0.1cpe:/a:mozilla:firefox_esr:24.0.1:::
mozillafirefox_esr24.3cpe:/a:mozilla:firefox_esr:24.3:::
mozillafirefox_esr24.5cpe:/a:mozilla:firefox_esr:24.5:::
mozillathunderbird24.4cpe:/a:mozilla:thunderbird:24.4:::
mozillathunderbird24.1cpe:/a:mozilla:thunderbird:24.1:::
mozillathunderbird24.2cpe:/a:mozilla:thunderbird:24.2:::
mozillathunderbird24.1.1cpe:/a:mozilla:thunderbird:24.1.1:::
mozillathunderbird24.0cpe:/a:mozilla:thunderbird:24.0:::
Rows per page:
1-10 of 201

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

9.6

Confidence

High

EPSS

0.041

Percentile

92.1%