PoC Index

CVE-2014-1510

CRITICAL 9.8EPSS 82.3%

The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment to trigger a window.open call.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
82.34% chance of exploitation in the next 30 days, 100th percentile
Published
2014-03-19
Updated
2024-08-06

Proof-of-concept exploits (1)

Metasploit modules (1)

ExploitDB entries (1)

References

Related