suse · CVE-2014-1502

Quick triage

Priority: critical Published: 2021-05-30 13:18:56 UTC Updated: 2026-04-18 18:44:02 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2014-1502 severity critical: SUSE including 37 source package names (MozillaFirefox-140.2.0-160000.1.2, MozillaFirefox-24.4.0esr-0.5.5.1, …), 55 product×package rows across 10 product lines (SUSE Linux Enterprise Desktop 11 SP3, SUSE Linux Enterprise Module for Desktop Applications 15, … (10 product lines)): Fixed 55.

Description:

The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.

cvelogic Threat Intelligence