CVE-2014-1480

The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a downloaded file, via a crafted web site.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
Affected Products (NVD)
VendorProductVersion
opensuseopensuse
11.4
opensuseopensuse
12.3
opensuseopensuse
13.1
oraclesolaris
11.3
canonicalubuntu_linux
12.04
canonicalubuntu_linux
12.10
canonicalubuntu_linux
13.10
mozillafirefox
𝑥
< 27.0
mozillaseamonkey
𝑥
< 2.24
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
lucid
ignored
precise
Fixed 27.0+build1-0ubuntu0.12.04.1
released
quantal
Fixed 27.0+build1-0ubuntu0.12.10.1
released
saucy
Fixed 27.0+build1-0ubuntu0.13.10.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
MozillaFirefox
suse enterprise sap 12 SP5
68.1.0-109.92.1
fixed
suse enterprise server 12 SP5
68.1.0-109.92.1
fixed
MozillaFirefox-translations-common
suse enterprise sap 12 SP5
68.1.0-109.92.1
fixed
suse enterprise server 12 SP5
68.1.0-109.92.1
fixed
References