CVE-2014-8643Mozilla Firefox vulnerability

CWE-2642 documents2 sources
Severity
7.1HIGHNVD
EPSS
1.3%
top 19.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 14
Latest updateMay 14

Description

Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging access to the GMP process, as demonstrated by the OpenH264 plugin's process.

CVSS vector

AV:N/AC:M/C:N/I:C/A:NExploitability: 8.6 | Impact: 6.9

Affected Packages2 packages

NVDmozilla/firefox34.0.5
NVDopensuse/opensuse13.1, 13.2+1

🔴Vulnerability Details

1
GHSA
GHSA-xf23-357c-2vmh: Mozilla Firefox before 352022-05-14