CVE-2014-1488: Canonical Ubuntu Linux

High severity, CVSS 10.0. EPSS: 7.2% chance of exploitation in the next 30 days.

The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-thread object-passing operation in conjunction with use of asm.js.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 12.10 only; version 13.10 only
  • Mozilla Firefox: before 27.0 (fixed in 27.0)
  • Mozilla Seamonkey: before 2.24 (fixed in 2.24)
  • Opensuse Opensuse: version 12.3 only; version 13.1 only
  • Oracle Solaris: version 11.3 only
  • Suse Linux Enterprise Desktop: version 11 only
  • Suse Linux Enterprise Server: version 11 only
  • Suse Linux Enterprise Software Development Kit: version 11 only

Published 2014-02-06. Last modified 2026-06-17.