CVE-2014-1510 is a critical vulnerability affecting Mozilla Firefox, Firefox ESR, Thunderbird, and SeaMonkey, allowing remote attackers to execute arbitrary JavaScript with chrome privileges. This is achieved by manipulating the Web IDL implementation to trigger a privileged window.open call. With a CVSS score of 9.8 (Critical) and an EPSS percentile of 98.7%, it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV, a Metasploit module exists, indicating readily available exploit code. The vulnerability has garnered significant community discussion and media coverage, highlighting its past relevance and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 28.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
>= 24.0, < 24.4CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 2.25CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* | ||
< 24.4CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.