Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across different JavaScript engines.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Nov 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Mozilla firefox Esr
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-06T09:42:35.868Z
Reserved: 2014-01-16T00:00:00
Link: CVE-2014-1481
No data.
Status : Deferred
Published: 2014-02-06T05:44:24.877
Modified: 2025-11-25T17:50:16.803
Link: CVE-2014-1481