10

CVE-2014-1488

The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-thread object-passing operation in conjunction with use of asm.js.

Data is provided by the National Vulnerability Database (NVD)
MozillaFirefox Version < 27.0
MozillaSeamonkey Version < 2.24
CanonicalUbuntu Linux Version12.04 SwEditionesm
CanonicalUbuntu Linux Version12.10
CanonicalUbuntu Linux Version13.10
OracleSolaris Version11.3
OpensuseOpensuse Version12.3
OpensuseOpensuse Version13.1
SuseLinux Enterprise Desktop Version11 Updatesp3
SuseLinux Enterprise Server Version11 Updatesp3 SwPlatform-
SuseLinux Enterprise Server Version11 Updatesp3 SwPlatformvmware
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.09% 0.769
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
http://www.securitytracker.com/id/1029717
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1029720
Third Party Advisory
VDB Entry
https://8pecxstudios.com/?page_id=44080
Broken Link
URL Repurposed
http://www.securityfocus.com/bid/65321
Third Party Advisory
VDB Entry