Lucene search

K
cve[email protected]CVE-2014-1480
HistoryFeb 06, 2014 - 5:44 a.m.

CVE-2014-1480

2014-02-0605:44:24
CWE-1021
web.nvd.nist.gov
45
mozilla
firefox
seamonkey
clickjacking
cve-2014-1480
security vulnerability
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

8.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.1%

The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a downloaded file, via a crafted web site.

Affected configurations

NVD
Node
opensuseopensuseMatch11.4
OR
opensuseopensuseMatch12.3
OR
opensuseopensuseMatch13.1
OR
suselinux_enterprise_desktopMatch11sp3
OR
suselinux_enterprise_serverMatch11sp3-
OR
suselinux_enterprise_serverMatch11sp3vmware
OR
suselinux_enterprise_software_development_kitMatch11sp3
Node
oraclesolarisMatch11.3
Node
canonicalubuntu_linuxMatch12.04esm
OR
canonicalubuntu_linuxMatch12.10
OR
canonicalubuntu_linuxMatch13.10
Node
mozillafirefoxRange<27.0
OR
mozillaseamonkeyRange<2.24

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

8.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.1%