V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2014-1483
DEB
Medium

Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive informat…

CVSS
4.3
Medium
EPSS
0.02
p82
Published
2014-01-01
Updated
2014-01-01
Description

Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.

Tags · CWE
CWE-1021
CAPEC-103
CAPEC-181
CAPEC-222
CAPEC-504
CAPEC-506
CAPEC-587
CAPEC-654
Affected products
Firefox < 27.0Seamonkey < 2.24
CVSS vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: P
Partial
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.025 · p82
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-504 · CWE-1021
└ via CAPEC-654 · CWE-1021
└ via CAPEC-654 · CWE-1021
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
icedoveTracked
iceweaselTracked
firefox*Tracked
linux_enterprise_desktop*Tracked
linux_enterprise_server*Tracked
opensuse*Tracked
seamonkey*Tracked
solaris*Tracked
suse_linux_enterprise_software_development_kit*Tracked
ubuntu_linux*Tracked
Source databases
DEB
CVE
Related vulnerabilities