CVE-2014-1511 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 83.6% (pctl 100)
Patch early
A public exploit exists.
Description
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 83.63% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-269 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-03-19 |
| Last modified | 2026-06-17 |
Affected (16)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| debian | debian linux |
| mozilla | firefox |
| mozilla | seamonkey |
| mozilla | thunderbird |
| opensuse | opensuse |
| redhat | enterprise linux desktop |
| redhat | enterprise linux eus |
| redhat | enterprise linux server |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server eus |
| redhat | enterprise linux server tus |
| redhat | enterprise linux workstation |
| suse | suse linux enterprise desktop |
| suse | suse linux enterprise server |
| suse | suse linux enterprise software development kit |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mozilla Firefox - WebIDL Privileged JavaScript Injection (Metasploit) | 2014-08-28 |
References
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00016.html
- http://rhn.redhat.com/errata/RHSA-2014-0310.html
- http://rhn.redhat.com/errata/RHSA-2014-0316.html
- http://www.debian.org/security/2014/dsa-2881
- http://www.debian.org/security/2014/dsa-2911
- http://www.mozilla.org/security/announce/2014/mfsa2014-29.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/66207
- http://www.ubuntu.com/usn/USN-2151-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=982909
- https://security.gentoo.org/glsa/201504-01
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00016.html
- http://rhn.redhat.com/errata/RHSA-2014-0310.html
- http://rhn.redhat.com/errata/RHSA-2014-0316.html
→ the Explorer · watch your stack · NVD