CVE-2014-1499
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/03/2014
Last modified:
12/04/2025
Description
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:* | ||
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:*:*:* | ||
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:* | ||
cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp3:*:*:*:*:*:* | ||
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* | 2.25 (excluding) | |
cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | 28.0 (excluding) | |
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
cpe:2.3:o:opensuse_project:opensuse:11.4:*:*:*:*:*:*:* | ||
cpe:2.3:o:opensuse_project:opensuse:12.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00016.html
- http://www.mozilla.org/security/announce/2014/mfsa2014-19.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=961512
- https://security.gentoo.org/glsa/201504-01
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00016.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00022.html
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00016.html
- http://www.mozilla.org/security/announce/2014/mfsa2014-19.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=961512
- https://security.gentoo.org/glsa/201504-01