View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2014-1499 severity critical: SUSE including 37 source package names (MozillaFirefox-140.2.0-160000.1.2, MozillaFirefox-24.4.0esr-0.5.5.1, …), 55 product×package rows across 10 product lines (SUSE Linux Enterprise Desktop 11 SP3, SUSE Linux Enterprise Module for Desktop Applications 15, … (10 product lines)): Fixed 55.
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.