CVE-2014-1510observed exploitation

CVE-2014-1510

Published · Updated

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 82%
from disclosure to weapon162 days
Published on NVDMar 19
1st PoC+162d
metasploitMar 17
VulnCheck+869d
exploitation probability
82%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
8 products (115 components)
Red Hat Enterprise Linux Desktop (v. 6) · Red Hat Enterprise Linux Workstation (v. 6) · Red Hat Enterprise Linux Desktop (v. 5 client) · Red Hat Enterprise Linux (v. 5 server) · Red Hat Enterprise Linux HPC Node Optional (v. 6) · and others 3
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment to trigger a window.open call.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.