CVE-2014-1526

EUVD-2014-1602
The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger, leading to unwrapping operations and calls to DOM methods on the unwrapped objects.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
𝑥
< 29.0
mozillaseamonkey
𝑥
< 2.26
canonicalubuntu_linux
12.04
canonicalubuntu_linux
12.10
canonicalubuntu_linux
13.10
canonicalubuntu_linux
14.04
opensuseopensuse
12.3
opensuseopensuse
13.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
lucid
ignored
precise
Fixed 29.0+build1-0ubuntu0.12.04.2
released
quantal
Fixed 29.0+build1-0ubuntu0.12.10.3
released
saucy
Fixed 29.0+build1-0ubuntu0.13.10.3
released
trusty
Fixed 29.0+build1-0ubuntu0.14.04.2
released