CVE-2014-1590

CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 3.10 % (91th)
3.10% Progress
Affected Products 4
Advisories 10

The XMLHttpRequest.prototype.send method in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to cause a denial of service (application crash) via a crafted JavaScript object.

Weaknesses
CWE-20
Improper Input Validation
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2014-12-11 11:59:04
(9 years ago)
Updated Date
2016-12-24 02:59:01
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 33.0 and prior versions cpe:2.3:a:mozilla:firefox <= 33.0
  Mozilla Firefox Esr 31.2 and prior versions cpe:2.3:a:mozilla:firefox_esr <= 31.2
  Mozilla Seamonkey 2.30 and prior versions cpe:2.3:a:mozilla:seamonkey <= 2.30
  Mozilla Thunderbird 31.2 and prior versions cpe:2.3:a:mozilla:thunderbird <= 31.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...