CVE-2014-1526

The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger, leading to unwrapping operations and calls to DOM methods on the unwrapped objects.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mozillaCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
VendorProductVersion
mozillafirefox
𝑥
< 29.0
mozillaseamonkey
𝑥
< 2.26
canonicalubuntu_linux
12.04
canonicalubuntu_linux
12.10
canonicalubuntu_linux
13.10
canonicalubuntu_linux
14.04
opensuseopensuse
12.3
opensuseopensuse
13.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
trusty
Fixed 29.0+build1-0ubuntu0.14.04.2
released
saucy
Fixed 29.0+build1-0ubuntu0.13.10.3
released
quantal
Fixed 29.0+build1-0ubuntu0.12.10.3
released
precise
Fixed 29.0+build1-0ubuntu0.12.04.2
released
lucid
ignored