CVE-2014-1526: Medium severity Mozilla Firefox vulnerability
The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger, leading to unwrapping operations and calls to DOM methods on the unwrapped objects.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mozilla Firefox (XrayWrapper)to a version that resolves this vulnerability.Fixed in 29.0 - Upgrade
Upgrade
SeaMonkey (XrayWrapper)to a version that resolves this vulnerability.Fixed in 2.26
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1526?
CVE-2014-1526 has been classified as a moderate severity vulnerability.
How do I fix CVE-2014-1526?
To fix CVE-2014-1526, upgrade Mozilla Firefox to version 29.0 or later and SeaMonkey to version 2.26 or later.
What software is affected by CVE-2014-1526?
CVE-2014-1526 affects Mozilla Firefox versions prior to 29.0 and SeaMonkey versions prior to 2.26, as well as specific Ubuntu and openSUSE versions.
Can CVE-2014-1526 be exploited remotely?
Yes, CVE-2014-1526 can be exploited by remote attackers through a crafted website that users visit on the debugger.
What are the consequences of exploiting CVE-2014-1526?
Exploiting CVE-2014-1526 allows attackers to bypass access restrictions, potentially leading to unauthorized operations on sensitive DOM objects.