CVE-2014-8636

The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named getter, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via unspecified vectors.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mozillaCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
mozillafirefox
𝑥
≤ 34.0.5
mozillaseamonkey
𝑥
≤ 2.31
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
utopic
Fixed 35.0+build3-0ubuntu0.14.10.2
released
trusty
Fixed 35.0+build3-0ubuntu0.14.04.2
released
precise
Fixed 35.0+build3-0ubuntu0.12.04.2
released
lucid
ignored
References