CVE-2014-1483

Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
Affected Products (NVD)
VendorProductVersion
oraclesolaris
11.3
canonicalubuntu_linux
12.04
canonicalubuntu_linux
12.10
canonicalubuntu_linux
13.10
mozillafirefox
𝑥
< 27.0
mozillaseamonkey
𝑥
< 2.24
susesuse_linux_enterprise_software_development_kit
11.0:sp3
opensuseopensuse
11.4
opensuseopensuse
12.3
opensuseopensuse
13.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
lucid
ignored
precise
Fixed 27.0+build1-0ubuntu0.12.04.1
released
quantal
Fixed 27.0+build1-0ubuntu0.12.10.1
released
saucy
Fixed 27.0+build1-0ubuntu0.13.10.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
MozillaFirefox
suse enterprise sap 12 SP5
68.1.0-109.92.1
fixed
suse enterprise server 12 SP5
68.1.0-109.92.1
fixed
MozillaFirefox-translations-common
suse enterprise sap 12 SP5
68.1.0-109.92.1
fixed
suse enterprise server 12 SP5
68.1.0-109.92.1
fixed
References