CVE-2014-8632
published 2014-12-11CVE-2014-8632: The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.02%
59.5th percentile
The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by leveraging property availability after XrayWrapper removal.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 33.0 | — |
| mozilla | seamonkey | <= 2.30 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Privileged access to security wrapped protected objects (MFSA 2014-91)
vendor_redhat·2014-12-03·CVSS 4.3
CVE-2014-8632 [MEDIUM] CWE-285 Mozilla: Privileged access to security wrapped protected objects (MFSA 2014-91)
Mozilla: Privileged access to security wrapped protected objects (MFSA 2014-91)
The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by leveraging property availability after XrayWrapper removal.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise L
GHSA
GHSA-6h2f-xfhj-5wr4: The structured-clone implementation in Mozilla Firefox before 34
ghsa_unreviewed·2022-05-17
CVE-2014-8632 [MEDIUM] CWE-284 GHSA-6h2f-xfhj-5wr4: The structured-clone implementation in Mozilla Firefox before 34
The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by leveraging property availability after XrayWrapper removal.
No detection rules found.
No public exploits indexed.
http://www.mozilla.org/security/announce/2014/mfsa2014-91.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1050340https://security.gentoo.org/glsa/201504-01http://www.mozilla.org/security/announce/2014/mfsa2014-91.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1050340https://security.gentoo.org/glsa/201504-01
2014-12-11
Published