CVE-2014-1487

HIGH

Mozilla Firefox < 27.0 - Origin Validation Error

Title source: rule

Description

The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.

References (33)

... and 13 more

Scores

CVSS v3 7.5
EPSS 0.0061
EPSS Percentile 69.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-346
Status draft

Affected Products (26)

mozilla/firefox < 27.0
mozilla/seamonkey < 2.24
mozilla/thunderbird < 24.3
fedoraproject/fedora
fedoraproject/fedora
suse/suse_linux_enterprise_software_development_kit
opensuse/opensuse
opensuse/opensuse
opensuse/opensuse
suse/suse_linux_enterprise_desktop
suse/suse_linux_enterprise_server
suse/suse_linux_enterprise_server
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
... and 11 more

Timeline

Published Feb 06, 2014
Tracked Since Feb 18, 2026