CVE-2014-1489
published 2014-02-06CVE-2014-1489: Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.93%
77.9th percentile
Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.
Affected
207 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| mozilla | firefox | <= 26.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_ubuntu9.8CRITICAL
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox regression
vendor_ubuntu·2014-02-19·CVSS 9.8
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: USN-2102-1 introduced a regression in Firefox.
USN-2102-1 fixed vulnerabilities in Firefox. The update introduced a
regression which could make Firefox crash under some circumstances. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Christian Holler, Terrence Cole, Jesse Ruderman, Gary Kwong, Eric
Rescorla, Jonathan Kew, Dan Gohman, Ryan VanderMeulen, Carsten Book,
Andrew Sutherland, Byron Campen, Nicholas Nethercote, Paul Adenot, David
Baron, Julian Seward and Sotaro Ikeda discovered multiple memory safety
issues in Firefox. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2014-02-10·CVSS 9.8
CVE-2014-1477 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Christian Holler, Terrence Cole, Jesse Ruderman, Gary Kwong, Eric
Rescorla, Jonathan Kew, Dan Gohman, Ryan VanderMeulen, Carsten Book,
Andrew Sutherland, Byron Campen, Nicholas Nethercote, Paul Adenot, David
Baron, Julian Seward and Sotaro Ikeda discovered multiple memory safety
issues in Firefox. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2014-1477,
CVE-2014-1478)
Cody Crews discovered a method to bypass System Only Wrappers. An attacker
could potentially e
Red Hat
Mozilla: Firefox default start page UI content invokable by script (MFSA 2014-10)
vendor_redhat·2014-02-04·CVSS 4.3
CVE-2014-1489 [MEDIUM] Mozilla: Firefox default start page UI content invokable by script (MFSA 2014-10)
Mozilla: Firefox default start page UI content invokable by script (MFSA 2014-10)
Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-wwpm-rgch-9v66: Mozilla Firefox before 27
ghsa_unreviewed·2022-05-14
CVE-2014-1489 [MEDIUM] GHSA-wwpm-rgch-9v66: Mozilla Firefox before 27
Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-49985 kernel: bpf: Don't use tnum_range on array range checking for poke descriptors
bugzilla·2025-06-18·CVSS 7.1
CVE-2022-49985 [HIGH] CVE-2022-49985 kernel: bpf: Don't use tnum_range on array range checking for poke descriptors
CVE-2022-49985 kernel: bpf: Don't use tnum_range on array range checking for poke descriptors
In the Linux kernel, the following vulnerability has been resolved:
bpf: Don't use tnum_range on array range checking for poke descriptors
Hsin-Wei reported a KASAN splat triggered by their BPF runtime fuzzer which
is based on a customized syzkaller:
BUG: KASAN: slab-out-of-bounds in bpf_int_jit_compile+0x1257/0x13f0
Read of size 8 at addr ffff888004e90b58 by task syz-executor.0/1489
CPU: 1 PID: 1489 Comm: syz-executor.0 Not tainted 5.19.0 #1
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
1.13.0-1ubuntu1.1 04/01/2014
Call Trace:
dump_stack_lvl+0x9c/0xc9
print_address_description.constprop.0+0x1f/0x1f0
? bpf_int_jit_compile+0x1257/0x13f0
kasan_report.cold+0xeb/0x197
? kvmalloc_nod
Bugzilla
CVE-2014-1489 Mozilla: Firefox default start page UI content invokable by script (MFSA 2014-10)
bugzilla·2014-02-04·CVSS 4.3
CVE-2014-1489 [MEDIUM] CVE-2014-1489 Mozilla: Firefox default start page UI content invokable by script (MFSA 2014-10)
CVE-2014-1489 Mozilla: Firefox default start page UI content invokable by script (MFSA 2014-10)
Yazan Tommalieh discovered a flaw that once users have viewed the default Firefox start page (about:home), subsequent pages they navigate to in that same tab could use script to activate the buttons that were on the about:home page. Most of these simply open Firefox dialogs such as Settings or History, which might alarm users. In some cases a malicious page could trigger session restore and cause data loss if the current tabs are replaced by a previously stored set.
External Reference:
http://www.mozilla.org/security/announce/2014/mfsa2014-10.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Yazan Tommalieh as the origin
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.htmlhttp://osvdb.org/102874http://secunia.com/advisories/56888http://www.mozilla.org/security/announce/2014/mfsa2014-10.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/65329http://www.securitytracker.com/id/1029717http://www.ubuntu.com/usn/USN-2102-1http://www.ubuntu.com/usn/USN-2102-2https://bugzilla.mozilla.org/show_bug.cgi?id=959531https://exchange.xforce.ibmcloud.com/vulnerabilities/90888https://security.gentoo.org/glsa/201504-01http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.htmlhttp://osvdb.org/102874http://secunia.com/advisories/56888http://www.mozilla.org/security/announce/2014/mfsa2014-10.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/65329http://www.securitytracker.com/id/1029717http://www.ubuntu.com/usn/USN-2102-1http://www.ubuntu.com/usn/USN-2102-2https://bugzilla.mozilla.org/show_bug.cgi?id=959531https://exchange.xforce.ibmcloud.com/vulnerabilities/90888https://security.gentoo.org/glsa/201504-01
2014-02-06
Published