CVE-2014-1502: Medium severity openSUSE openSUSE vulnerability
The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1502?
CVE-2014-1502 is considered a medium severity vulnerability that allows bypassing the Same Origin Policy.
How do I fix CVE-2014-1502?
To fix CVE-2014-1502, upgrade to Mozilla Firefox version 28.0 or later, or SeaMonkey version 2.25 or later.
Who is affected by CVE-2014-1502?
CVE-2014-1502 affects users of Mozilla Firefox versions before 28.0 and SeaMonkey versions before 2.25, along with specific versions of openSUSE and SUSE Linux Enterprise.
What is the impact of exploiting CVE-2014-1502?
Exploitation of CVE-2014-1502 could allow remote attackers to render content from a different domain, compromising web application security.
Are there any workarounds for CVE-2014-1502?
There are no known workarounds for CVE-2014-1502 other than updating the affected software to a fixed version.