CVE-2014-1586
Summary
| CVE | CVE-2014-1586 |
|---|---|
| State | PUBLISHED |
| Assigner | mozilla |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-15 10:55:07 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | content/base/src/nsDocument.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does not consider whether WebRTC video sharing is occurring, which allows remote attackers to obtain sensitive information from the local camera in certain IFRAME situations by maintaining a session after the user temporarily navigates away. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 30.0 | All | All | All |
| Application | Mozilla | Firefox | 31.0 | All | All | All |
| Application | Mozilla | Firefox | 31.1.0 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Thunderbird | 31.0 | All | All | All |
| Application | Mozilla | Thunderbird | 31.1.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| openSUSE-SU-2014:1346-1: moderate: update for MozillaThunderbird | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| openSUSE-SU-2014:1345-1: moderate: update for firefox, mozilla-nspr, moz | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Mozilla Firefox Bugs Let Remote Users Execute Arbitrary Code, Bypass Same Origin-Policy, and Obtain Potentially Sensitive Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| openSUSE-SU-2014:1343-1: moderate: update for MozillaThunderbird | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| USN-2372-1: Firefox vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Oracle Solaris Third Party Bulletin - April 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Mozilla Firefox/Thunderbird CVE-2014-1586 Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| openSUSE-SU-2014:1344-1: moderate: update for firefox, mozilla-nspr, moz | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Gentoo Security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Debian -- Security Information -- DSA-3061-1 icedove | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Security Advisory SA62023 - SUSE update for firefox, mozilla-nspr, and mozilla-nss - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 1062981 – (CVE-2014-1586) Navigating away from a page with camera sharing in an iframe leaves camera recording | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| [SECURITY] Fedora 21 Update: firefox-33.0-1.fc21 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Security Advisory SA61387 - Debian update for icedove - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-3050-1 iceweasel | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Mozilla Thunderbird Bugs Let Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Inconsistent video sharing within iframe — Mozilla | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| Security Advisory SA62022 - SUSE update for firefox, mozilla-nspr, mozilla-nss, and seamonkey - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA62021 - SUSE update for MozillaThunderbird - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| USN-2373-1: Thunderbird vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [security-announce] openSUSE-SU-2015:0138-1: important: Firefox update t | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [SECURITY] Fedora 20 Update: firefox-33.0-1.fc20 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [security-announce] openSUSE-SU-2015:1266-1: important: Mozilla (Firefox | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.