The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade thunderbirdUpgrade firefox | Dec 1, 2016 | Feb 6, 2014 |
| Freebsd | — | Upgrade linux-thunderbirdUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade firefoxUpgrade linux-firefoxUpgrade thunderbird | Dec 10, 2025 | Feb 4, 2014 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey.Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox.Upgrade www-client/seamonkey-bin.Upgrade www-client/firefox-bin.Upgrade dev-libs/nspr. | Oct 30, 2017 | Feb 6, 2014 |
| Mfsa2014 09 | — | Upgrade to Mozilla Firefox ESR version 24.3Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 27.0 | Feb 5, 2014 | Feb 4, 2014 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.24.0 | Dec 8, 2014 | Feb 6, 2014 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 24.3 | Feb 5, 2014 | Feb 4, 2014 |
| Oracle Solaris | — | Upgrade runtime/tcl-8/tcl-sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3/documentation to version 3.8.2-0.175.2.5.0.4.0 on Solaris 11.2Upgrade database/sqlite-3 to version 3.8.2-0.175.2.5.0.4.0 on Solaris 11.2Upgrade runtime/tcl-8/tcl-sqlite-3 to version 3.8.2-0.175.2.5.0.4.0 on Solaris 11.2Upgrade database/sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3/documentation to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade consolidation/desktop/desktop-incorporation to version 0.5.11-0.175.3.0.0.28.0 on Solaris 11.3Upgrade web/browser/firefox to version 24.7.0-0.175.2.5.0.4.0 on Solaris 11.2Upgrade web/browser/firefox to version 38.4.0-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | Feb 6, 2014 |
| Oracle_linux | — | Upgrade thunderbirdUpgrade firefox | Oct 16, 2024 | Feb 6, 2014 |
| Suse | — | Upgrade MozillaFirefoxUpgrade MozillaFirefox-translations-commonUpgrade mozilla-nspr-32bitUpgrade libsoftokn3-32bitUpgrade MozillaFirefox-translationsUpgrade mozilla-nss-develUpgrade MozillaThunderbirdUpgrade firefox-libgcc_s1Upgrade libfreebl3-32bitUpgrade libsoftokn3-x86Upgrade mozilla-nsprUpgrade mozilla-nss-x86Upgrade libfreebl3Upgrade MozillaThunderbird-translations-commonUpgrade libfreebl3-x86Upgrade MozillaThunderbird-develUpgrade MozillaFirefox-develUpgrade mozilla-nssUpgrade MozillaFirefox-translations-otherUpgrade libsoftokn3Upgrade MozillaFirefox-branding-SLEDUpgrade MozillaThunderbird-translations-otherUpgrade mozilla-nss-32bitUpgrade firefox-libstdc++6Upgrade mozilla-nss-tools | Dec 18, 2015 | Feb 6, 2014 |
| Ubuntu | — | Upgrade thunderbirdUpgrade firefox | Nov 8, 2024 | Feb 6, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub