CVE-2014-1583

The Alarm API in Mozilla Firefox before 33.0 and Firefox ESR 31.x before 31.2 does not properly restrict toJSON calls, which allows remote attackers to bypass the Same Origin Policy via crafted API calls that access sensitive information within the JSON data of an alarm.
References
Link Resource
http://lists.fedoraproject.org/pipermail/package-announce/2014-November/141796.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141085.html
http://lists.opensuse.org/opensuse-updates/2014-11/msg00001.html
http://lists.opensuse.org/opensuse-updates/2014-11/msg00002.html
http://rhn.redhat.com/errata/RHSA-2014-1635.html
http://secunia.com/advisories/61854
http://secunia.com/advisories/62022
http://secunia.com/advisories/62023
http://www.debian.org/security/2014/dsa-3050
http://www.mozilla.org/security/announce/2014/mfsa2014-82.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
http://www.securityfocus.com/bid/70424
http://www.securitytracker.com/id/1031028
http://www.securitytracker.com/id/1031030
http://www.ubuntu.com/usn/USN-2372-1
https://advisories.mageia.org/MGASA-2014-0421.html
https://bugzilla.mozilla.org/show_bug.cgi?id=1015540
https://security.gentoo.org/glsa/201504-01
http://lists.fedoraproject.org/pipermail/package-announce/2014-November/141796.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141085.html
http://lists.opensuse.org/opensuse-updates/2014-11/msg00001.html
http://lists.opensuse.org/opensuse-updates/2014-11/msg00002.html
http://rhn.redhat.com/errata/RHSA-2014-1635.html
http://secunia.com/advisories/61854
http://secunia.com/advisories/62022
http://secunia.com/advisories/62023
http://www.debian.org/security/2014/dsa-3050
http://www.mozilla.org/security/announce/2014/mfsa2014-82.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
http://www.securityfocus.com/bid/70424
http://www.securitytracker.com/id/1031028
http://www.securitytracker.com/id/1031030
http://www.ubuntu.com/usn/USN-2372-1
https://advisories.mageia.org/MGASA-2014-0421.html
https://bugzilla.mozilla.org/show_bug.cgi?id=1015540
https://security.gentoo.org/glsa/201504-01
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:30.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.1.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:mozilla:firefox:31.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:31.1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:04

Type Values Removed Values Added
References () http://lists.fedoraproject.org/pipermail/package-announce/2014-November/141796.html - () http://lists.fedoraproject.org/pipermail/package-announce/2014-November/141796.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141085.html - () http://lists.fedoraproject.org/pipermail/package-announce/2014-October/141085.html -
References () http://lists.opensuse.org/opensuse-updates/2014-11/msg00001.html - () http://lists.opensuse.org/opensuse-updates/2014-11/msg00001.html -
References () http://lists.opensuse.org/opensuse-updates/2014-11/msg00002.html - () http://lists.opensuse.org/opensuse-updates/2014-11/msg00002.html -
References () http://rhn.redhat.com/errata/RHSA-2014-1635.html - () http://rhn.redhat.com/errata/RHSA-2014-1635.html -
References () http://secunia.com/advisories/61854 - () http://secunia.com/advisories/61854 -
References () http://secunia.com/advisories/62022 - () http://secunia.com/advisories/62022 -
References () http://secunia.com/advisories/62023 - () http://secunia.com/advisories/62023 -
References () http://www.debian.org/security/2014/dsa-3050 - () http://www.debian.org/security/2014/dsa-3050 -
References () http://www.mozilla.org/security/announce/2014/mfsa2014-82.html - Vendor Advisory () http://www.mozilla.org/security/announce/2014/mfsa2014-82.html - Vendor Advisory
References () http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html - () http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html -
References () http://www.securityfocus.com/bid/70424 - () http://www.securityfocus.com/bid/70424 -
References () http://www.securitytracker.com/id/1031028 - () http://www.securitytracker.com/id/1031028 -
References () http://www.securitytracker.com/id/1031030 - () http://www.securitytracker.com/id/1031030 -
References () http://www.ubuntu.com/usn/USN-2372-1 - () http://www.ubuntu.com/usn/USN-2372-1 -
References () https://advisories.mageia.org/MGASA-2014-0421.html - () https://advisories.mageia.org/MGASA-2014-0421.html -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1015540 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1015540 -
References () https://security.gentoo.org/glsa/201504-01 - () https://security.gentoo.org/glsa/201504-01 -

21 Oct 2024, 13:55

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox_esr:31.1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:31.0:*:*:*:*:*:*:*

Information

Published : 2014-10-15 10:55

Updated : 2024-11-21 02:04


NVD link : CVE-2014-1583

Mitre link : CVE-2014-1583

CVE.ORG link : CVE-2014-1583


JSON object : View

Products Affected

mozilla

  • firefox