CVE-2014-1483

Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.
Configurations

Configuration 1 (hide)

cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:suse:suse_linux_enterprise_software_development_kit:11.0:sp3:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:-:*:*
cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:vmware:*:*

History

14 Feb 2024, 01:17

Type Values Removed Values Added
References () https://8pecxstudios.com/?page_id=44080 - Broken Link () https://8pecxstudios.com/?page_id=44080 - Broken Link, URL Repurposed

Information

Published : 2014-02-06 05:44

Updated : 2024-02-14 01:17


NVD link : CVE-2014-1483

Mitre link : CVE-2014-1483

CVE.ORG link : CVE-2014-1483


JSON object : View

Products Affected

opensuse

  • opensuse

mozilla

  • seamonkey
  • firefox

suse

  • linux_enterprise_server
  • suse_linux_enterprise_software_development_kit
  • linux_enterprise_desktop

canonical

  • ubuntu_linux

oracle

  • solaris
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames