CVE-2014-1511 is a critical vulnerability affecting Mozilla Firefox (before 28.0), Firefox ESR (before 24.4), Thunderbird (before 24.4), and SeaMonkey (before 2.25) that allows remote attackers to bypass the popup blocker through unspecified vectors. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low attack complexity, and high potential impact on confidentiality, integrity, and availability. While not listed on the KEV catalog, exploit intelligence indicates the existence of Metasploit modules, specifically "Firefox WebIDL Privileged Javascript Injection," suggesting readily available exploit code. The vulnerability has garnered significant community discussion and media coverage, including articles linking it to exploit kits, highlighting its potential for real-world exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 28.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
>= 24.0, < 24.4CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 2.25CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* | ||
< 24.4CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.