CVE-2014-1481: High severity Mozilla Firefox vulnerability
Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across different JavaScript engines.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 27.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 24.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.24
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1481?
CVE-2014-1481 has a severity rating of medium, as it allows remote attackers to bypass restrictions on window objects.
How do I fix CVE-2014-1481?
To fix CVE-2014-1481, users should update to the latest version of Mozilla Firefox, Firefox ESR, Thunderbird, or SeaMonkey as applicable.
What versions are affected by CVE-2014-1481?
CVE-2014-1481 affects Mozilla Firefox versions before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24.
Who is impacted by CVE-2014-1481?
Users of Mozilla Firefox, Firefox ESR, Thunderbird, and SeaMonkey prior to their respective patched versions are impacted by CVE-2014-1481.
What type of vulnerability is CVE-2014-1481?
CVE-2014-1481 is a security vulnerability that involves inconsistencies in native getter methods across different JavaScript engines.