SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-1480

The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a…

MEDIUM 4.3EPSS 2.70%

Does this matter?

Lower severity and a low EPSS score (2.70%). Track it; it rarely justifies an emergency change on its own.

Description

The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a downloaded file, via a crafted web site.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
2.70% probability · 85th percentile
CISA KEV
Not listed
Weakness
CWE-1021
Affected
opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · oracle/solaris · canonical/ubuntu linux · mozilla/firefox · mozilla/seamonkey
Source
security@mozilla.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.