CVE-2014-1487
HIGHMozilla Firefox < 27.0 - Origin Validation Error
Title source: ruleDescription
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.
References (33)
... and 13 more
Scores
CVSS v3
7.5
EPSS
0.0061
EPSS Percentile
69.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-346
Status
draft
Affected Products (26)
mozilla/firefox
< 27.0
mozilla/seamonkey
< 2.24
mozilla/thunderbird
< 24.3
fedoraproject/fedora
fedoraproject/fedora
suse/suse_linux_enterprise_software_development_kit
opensuse/opensuse
opensuse/opensuse
opensuse/opensuse
suse/suse_linux_enterprise_desktop
suse/suse_linux_enterprise_server
suse/suse_linux_enterprise_server
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
... and 11 more
Timeline
Published
Feb 06, 2014
Tracked Since
Feb 18, 2026