CVE-2014-1502: Mozilla Firefox

Medium severity, CVSS 6.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.

Affected products

  • Mozilla Firefox: before 28.0 (fixed in 28.0)
  • Mozilla Seamonkey: before 2.25 (fixed in 2.25)
  • Opensuse Opensuse: version 13.1 only
  • Opensuse Project Opensuse: version 11.4 only; version 12.3 only
  • Oracle Solaris: version 11.3 only
  • Suse Linux Enterprise Desktop: version 11 only
  • Suse Linux Enterprise Server: version 11 only
  • Suse Linux Enterprise Software Development Kit: version 11 only

Published 2014-03-19. Last modified 2026-06-17.