CVE-2014-1499Mozilla Firefox vulnerability

6 documents6 sources
Severity
4.3MEDIUMNVD
EPSS
0.6%
top 30.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 19
Latest updateMay 13

Description

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages8 packages

NVDmozilla/firefox< 28.0
NVDmozilla/seamonkey< 2.25
NVDoracle/solaris11.3
NVDopensuse_project/opensuse11.4, 12.3+1

🔴Vulnerability Details

2
GHSA
GHSA-p22j-xcm8-97mv: Mozilla Firefox before 282022-05-13
CVEList
CVE-2014-1499: Mozilla Firefox before 282014-03-19

📋Vendor Advisories

2
Red Hat
Mozilla: Spoofing attack on WebRTC permission prompt (MFSA 2014-19)2014-03-18
Ubuntu
Firefox vulnerabilities2014-03-18

💬Community

1
Bugzilla
CVE-2014-1499 Mozilla: Spoofing attack on WebRTC permission prompt (MFSA 2014-19)2014-03-17
CVE-2014-1499 — Mozilla Firefox vulnerability | cvebase