vendor:
N/A
by:
Marius Mlynski, joev
9,8
CVSS
CRITICAL
Privilege Escalation Vulnerabilities in Firefox's Javascript APIs
N/A
CWE
Product Name: N/A
Affected Version From: 22.0
Affected Version To: 27.0
Patch Exists: YES
Related CWE: CVE-2014-1510, CVE-2014-1511
CPE: N/A
Metasploit:
https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2014-1510/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-1510/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2014-1510/, https://www.rapid7.com/db/vulnerabilities/mozilla-seamonkey-cve-2014-1510/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2014-1510/, https://www.rapid7.com/db/vulnerabilities/mfsa2014-29-cve-2014-1510/, https://www.rapid7.com/db/vulnerabilities/mozilla-thunderbird-cve-2014-1510/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2014-1511/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2014-1511/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-1511/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2014-1511/, https://www.rapid7.com/db/vulnerabilities/mozilla-seamonkey-cve-2014-1511/, https://www.rapid7.com/db/vulnerabilities/mfsa2014-29-cve-2014-1511/, https://www.rapid7.com/db/vulnerabilities/mozilla-thunderbird-cve-2014-1511/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Firefox
2014
Firefox WebIDL Privileged Javascript Injection
This exploit gains remote code execution on Firefox 22-27 by abusing two separate privilege escalation vulnerabilities in Firefox's Javascript APIs.
Mitigation:
N/A