Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across different JavaScript engines.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mozilla
Published: 2014-02-06T02:00:00
Updated: 2024-08-06T09:42:35.868Z
Reserved: 2014-01-16T00:00:00
Link: CVE-2014-1481
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-02-06T05:44:24.877
Modified: 2024-11-21T02:04:21.300
Link: CVE-2014-1481
Redhat