V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2014-1480
DEB
Medium

The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button s…

CVSS
4.3
Medium
EPSS
0.03
p83
Published
2014-01-01
Updated
2014-01-01
Description

The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a downloaded file, via a crafted web site.

Tags · CWE
CWE-1021
CAPEC-103
CAPEC-181
CAPEC-222
CAPEC-504
CAPEC-506
CAPEC-587
CAPEC-654
Affected products
Firefox < 27.0Seamonkey < 2.24
CVSS vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.027 · p83
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-504 · CWE-1021
└ via CAPEC-654 · CWE-1021
└ via CAPEC-654 · CWE-1021
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
icedoveTracked
iceweaselTracked
firefox*Tracked
linux_enterprise_desktop*Tracked
linux_enterprise_server*Tracked
linux_enterprise_software_development_kit*Tracked
opensuse*Tracked
seamonkey*Tracked
solaris*Tracked
ubuntu_linux*Tracked
Source databases
DEB
CVE
Related vulnerabilities