4.3
CVSSv2

CVE-2014-8632

Published: 11/12/2014 Updated: 22/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The structured-clone implementation in Mozilla Firefox prior to 34.0 and SeaMonkey prior to 2.31 does not properly interact with XrayWrapper property filtering, which allows remote malicious users to bypass intended DOM object restrictions by leveraging property availability after XrayWrapper removal.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla seamonkey

Vendor Advisories

Mozilla Foundation Security Advisory 2014-91 Privileged access to security wrapped protected objects Announced December 2, 2014 Reporter Bobby Holley Impact Moderate Products Firefox, SeaMonkey Fixed in ...