Lucene search

K
cveMozillaCVE-2014-1586
HistoryOct 15, 2014 - 10:55 a.m.

CVE-2014-1586

2014-10-1510:55:07
mozilla
web.nvd.nist.gov
51
cve-2014-1586
mozilla firefox
thunderbird
remote attackers
webrtc
camera issue
information leakage

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

8.6

Confidence

High

EPSS

0.005

Percentile

75.5%

content/base/src/nsDocument.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does not consider whether WebRTC video sharing is occurring, which allows remote attackers to obtain sensitive information from the local camera in certain IFRAME situations by maintaining a session after the user temporarily navigates away.

Affected configurations

Nvd
Node
mozillafirefoxRange32.0
OR
mozillafirefoxMatch30.0
OR
mozillafirefoxMatch31.0
OR
mozillafirefoxMatch31.1.0
Node
mozillathunderbirdMatch31.0
OR
mozillathunderbirdMatch31.1.0
Node
mozillafirefox_esrMatch31.0
OR
mozillafirefox_esrMatch31.1.0
VendorProductVersionCPE
mozillafirefox31.0cpe:/a:mozilla:firefox:31.0:::
mozillafirefox30.0cpe:/a:mozilla:firefox:30.0:::
mozillafirefoxcpe:/a:mozilla:firefox::::
mozillafirefox31.1.0cpe:/a:mozilla:firefox:31.1.0:::

References

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

8.6

Confidence

High

EPSS

0.005

Percentile

75.5%