- EPSS 0.55%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger gene...
CVE-2014-1499
- EPSS 0.61%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.
- EPSS 2.26%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution.
CVE-2014-1502
- EPSS 0.28%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecifi...
CVE-2014-1504
- EPSS 0.61%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted ...
CVE-2014-1505
- EPSS 0.54%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the S...
CVE-2014-1508
- EPSS 0.99%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process memory, cause a denial of...
CVE-2014-1509
- EPSS 0.81%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25, allows remote attackers to execute arbitrary code via a ...
CVE-2014-1510
- EPSS 77.56%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment t...
CVE-2014-1511
- EPSS 75.96%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.