CVE-2014-1590

Severity
4.3MEDIUM
EPSS
1.0%
top 22.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateMay 17

Description

The XMLHttpRequest.prototype.send method in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to cause a denial of service (application crash) via a crafted JavaScript object.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages5 packages

NVDmozilla/firefox31.2+1
Ubuntufirefox< 34.0+build2-0ubuntu0.14.04.1
Ubuntuthunderbird< 1:31.3.0+build1-0ubuntu0.14.04.1

🔴Vulnerability Details

4
GHSA
GHSA-q3gw-5r7r-5q58: The XMLHttpRequest2022-05-17
CVEList
CVE-2014-1590: The XMLHttpRequest2014-12-11
OSV
thunderbird vulnerabilities2014-12-03
OSV
CVE-2014-1590: The XMLHttpRequest2014-12-02

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2014-12-03
Red Hat
Mozilla: XMLHttpRequest crashes with some input streams (MFSA 2014-85)2014-12-02
Ubuntu
Firefox vulnerabilities2014-12-02

💬Community

1
Bugzilla
CVE-2014-1590 Mozilla: XMLHttpRequest crashes with some input streams (MFSA 2014-85)2014-12-01