CVE-2014-1483: Canonical Ubuntu Linux
Medium severity, CVSS 5.0. EPSS: 2.5% chance of exploitation in the next 30 days.
Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 12.10 only; version 13.10 only
- Mozilla Firefox: before 27.0 (fixed in 27.0)
- Mozilla Seamonkey: before 2.24 (fixed in 2.24)
- Opensuse Opensuse: version 11.4 only; version 12.3 only; version 13.1 only
- Oracle Solaris: version 11.3 only
- Suse Linux Enterprise Desktop: version 11 only
- Suse Linux Enterprise Server: version 11 only
- Suse Suse Linux Enterprise Software Development Kit: version 11.0 only
Published 2014-02-06. Last modified 2026-06-17.