cbcvebase.
CVE-2014-8639
published 2015-01-14

CVE-2014-8639: Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers…

PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.90%
77.6th percentile
Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.

Affected

11 ranges
VendorProductVersion rangeFixed in
mozillafirefox<= 34.0.5
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox>= 0 < 35.0.1+build1-0ubuntu0.14.04.135.0.1+build1-0ubuntu0.14.04.1
mozillafirefox>= 0 < 35.0+build3-0ubuntu0.14.04.235.0+build3-0ubuntu0.14.04.2
mozillafirefox_esr
mozillaseamonkey<= 2.31
mozillathunderbird<= 31.3.0
mozillathunderbird>= 0 < 1:31.4.0+build1-0ubuntu0.14.04.11:31.4.0+build1-0ubuntu0.14.04.1

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.