The Program::getActiveUniformMaxLength function in libGLESv2/Program.cpp in libGLESv2.dll in the WebGLES library in Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox 4.x before 4.0.1 on Windows and in the GPU process in Google Chrome before 10.0.648.205 on Windows, allows remote attackers to execute arbitrary code via unspecified vectors, related to an "off-by-three" error.
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14466
https://exchange.xforce.ibmcloud.com/vulnerabilities/66766
https://bugzilla.mozilla.org/show_bug.cgi?id=623791
http://www.vupen.com/english/advisories/2011/1006
http://www.securitytracker.com/id?1025377
http://www.securityfocus.com/bid/47377
http://www.mozilla.org/security/announce/2011/mfsa2011-17.html
http://secunia.com/advisories/44141
http://googlechromereleases.blogspot.com/2011/04/stable-channel-update.html