10
CVSSv2

CVE-2014-1488

Published: 06/02/2014 Updated: 14/02/2024
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Web workers implementation in Mozilla Firefox prior to 27.0 and SeaMonkey prior to 2.24 allows remote malicious users to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-thread object-passing operation in conjunction with use of asm.js.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla seamonkey

mozilla firefox

canonical ubuntu linux 13.10

canonical ubuntu linux 12.10

canonical ubuntu linux 12.04

oracle solaris 11.3

suse linux enterprise desktop 11

suse linux enterprise server 11

opensuse opensuse 12.3

suse linux enterprise software development kit 11

opensuse opensuse 13.1

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
USN-2102-1 introduced a regression in Firefox ...
Mozilla Foundation Security Advisory 2014-11 Crash when using web workers with asmjs Announced February 4, 2014 Reporter Soeren Balko Impact Critical Products Firefox, Firefox ESR, SeaMonkey Fixed in ...
The Web workers implementation in Mozilla Firefox before 270 and SeaMonkey before 224 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-thread object-passing operation in conjunction with use of asmjs ...