CVE-2014-1502

Opensuse < 28.0 - Origin Validation Error

Title source: rule
STIX 2.1

Description

The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.

References (8)

Core 8
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201504-01
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00016.html
Mailing List, Third Party Advisory x_refsource_confirm
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=972622
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00016.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00022.html

Scores

EPSS 0.0028
EPSS Percentile 51.8%

Details

CWE
CWE-346
Status published
Products (9)
mozilla/firefox < 28.0
mozilla/seamonkey < 2.25
opensuse/opensuse 13.1
opensuse_project/opensuse 11.4
opensuse_project/opensuse 12.3
oracle/solaris 11.3
suse/linux_enterprise_desktop 11 sp3
suse/linux_enterprise_server 11 sp3 (2 CPE variants)
suse/linux_enterprise_software_development_kit 11 sp3
Published Mar 19, 2014
Tracked Since Feb 18, 2026