CVE-2014-1501
- EPSS 0.23%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.
CVE-2014-1502
- EPSS 0.28%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecifi...
CVE-2014-1504
- EPSS 0.61%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted ...
CVE-2014-2309
- EPSS 0.91%
- Veröffentlicht 11.03.2014 13:01:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ip6_route_add function in net/ipv6/route.c in the Linux kernel through 3.13.6 does not properly count the addition of routes, which allows remote attackers to cause a denial of service (memory consumption) via a flood of ICMPv6 Router Advertiseme...
CVE-2014-0069
- EPSS 0.05%
- Veröffentlicht 28.02.2014 06:18:54
- Zuletzt bearbeitet 29.04.2026 01:13:23
The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes, which allows local users to obtain sensitive information from ke...
CVE-2014-1874
- EPSS 0.06%
- Veröffentlicht 28.02.2014 06:18:54
- Zuletzt bearbeitet 29.04.2026 01:13:23
The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel before 3.13.4 allows local users to cause a denial of service (system crash) by leveraging the CAP_MAC_ADMIN capability to set a zero-length security cont...
- EPSS 1.09%
- Veröffentlicht 06.02.2014 05:44:25
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-thread object-passing operation...
CVE-2014-1489
- EPSS 1.25%
- Veröffentlicht 06.02.2014 05:44:25
- Zuletzt bearbeitet 29.04.2026 01:13:23
Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.
CVE-2014-1490
- EPSS 1.57%
- Veröffentlicht 06.02.2014 05:44:25
- Zuletzt bearbeitet 29.04.2026 01:13:23
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to ca...
CVE-2014-1491
- EPSS 0.53%
- Veröffentlicht 06.02.2014 05:44:25
- Zuletzt bearbeitet 29.04.2026 01:13:23
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellma...