Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2014-1487

EPSS 0.61% · P70
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2014-1487

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
多款Mozilla产品信任管理问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mozilla Firefox、SeaMonkey和Thunderbird都是由美国Mozilla基金会开发。Firefox是一款开源Web浏览器。SeaMonkey是一套免费、开源以及跨平台的网络套装软件。Thunderbird是从Mozilla Application Suite中独立出来的一套电子邮件客户端软件。 多款Mozilla产品中的Web Worker中存在安全漏洞。远程攻击者可借助错误消息利用该漏洞绕过同源策略(Same Origin Policy),获取敏感的身份验证信息。以下版本受到影
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2014-1487

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2014-1487

Please Login to view more intelligence information

Same Patch Batch · n/a · 2014-02-06 · 48 CVEs total

CVE-2014-1479多款Mozilla产品权限许可和访问控制问题漏洞
CVE-2014-1486多款Mozilla产品‘imgRequestProxy’函数释放后重用漏洞
CVE-2014-1478Mozilla Firefox/SeaMonkey 内存损坏漏洞
CVE-2014-1485Mozilla Firefox/SeaMonkey 安全漏洞
CVE-2014-1488Mozilla Firefox/SeaMonkey 资源管理错误漏洞
CVE-2014-1489Mozilla Firefox 权限许可和访问控制漏洞
CVE-2014-1490Mozilla Network Security Services 竞争条件漏洞
CVE-2014-1491Mozilla Network Security Services 加密问题漏洞
CVE-2014-1484Mozilla Firefox 信息泄露漏洞
CVE-2014-1481多款Mozilla产品权限许可和访问控制漏洞
CVE-2014-1482多款Mozilla产品‘RasterImage.cpp’文件权限许可和访问控制问题漏洞
CVE-2014-1477多款Mozilla产品浏览器引擎安全漏洞
CVE-2014-0020Pidgin libpurple IRC协议插件输入验证漏洞
CVE-2013-7321D-Link DAP-2553 Access Point 跨站脚本漏洞
CVE-2013-7320D-Link DAP-2253 Access Point 跨站请求伪造漏洞
CVE-2013-7319WordPress Download Manager 跨站脚本漏洞
CVE-2013-6486Pidgin‘gtkutils.c’文件输入验证漏洞
CVE-2013-6485Pidgin libpurple‘util.c’文件缓冲区溢出漏洞
CVE-2013-6484Pidgin libpurple STUN协议输入验证漏洞
CVE-2013-6483Pidgin libpurple XMPP协议插件输入验证漏洞

Showing top 20 of 48 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2014-1487

No comments yet


Leave a comment