CVE-2014-1480
The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a…
Does this matter?
Lower severity and a low EPSS score (2.70%). Track it; it rarely justifies an emergency change on its own.
Description
The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a downloaded file, via a crafted web site.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.70% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1021
- Affected
- opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · oracle/solaris · canonical/ubuntu linux · mozilla/firefox · mozilla/seamonkey
- Source
- security@mozilla.org
References
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.htmlMailing List, Third Party Advisory
- http://osvdb.org/102867Broken Link
- http://secunia.com/advisories/56888Broken Link
- http://www.mozilla.org/security/announce/2014/mfsa2014-03.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlThird Party Advisory
- http://www.securityfocus.com/bid/65331Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029717Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029720Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2102-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2102-2Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=916726Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90897Third Party Advisory, VDB Entry
- https://security.gentoo.org/glsa/201504-01Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.htmlMailing List, Third Party Advisory
- http://osvdb.org/102867Broken Link
- http://secunia.com/advisories/56888Broken Link
- http://www.mozilla.org/security/announce/2014/mfsa2014-03.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlThird Party Advisory
- http://www.securityfocus.com/bid/65331Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029717Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029720Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2102-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2102-2Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=916726Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90897Third Party Advisory, VDB Entry
- https://security.gentoo.org/glsa/201504-01Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.