SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-1499

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.

MEDIUM 4.3EPSS 1.95%

Does this matter?

Lower severity and a low EPSS score (1.95%). Track it; it rarely justifies an emergency change on its own.

Description

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
1.95% probability · 79th percentile
CISA KEV
Not listed
Affected
suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · mozilla/seamonkey · oracle/solaris · mozilla/firefox · opensuse/opensuse · opensuse project/opensuse
Source
security@mozilla.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.