CVE-2014-8631

EUVD-2014-8468
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 supports native-interface passing, which allows remote attackers to bypass intended DOM object restrictions via a call to an unspecified method.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
𝑥
≤ 33.0
mozillaseamonkey
𝑥
≤ 2.30
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
lucid
ignored
precise
Fixed 34.0
released
trusty
Fixed 34.0
released
utopic
Fixed 34.0
released
thunderbird
lucid
ignored
precise
not-affected
trusty
dne
utopic
not-affected