CVE-2014-8632: Medium severity firefox vulnerability
Published Dec 11, 2014
·Updated
The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by leveraging property availability after XrayWrapper removal.
Affected Software
2 affected components
Mozilla Firefox<=33.0
Mozilla SeaMonkey<=2.30
Event History
Dec 11, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8632?
CVE-2014-8632 has been classified as a medium-severity vulnerability.
2
How do I fix CVE-2014-8632?
To remediate CVE-2014-8632, upgrade Mozilla Firefox to version 34.0 or later, or SeaMonkey to version 2.31 or later.
3
Which versions of Firefox are affected by CVE-2014-8632?
CVE-2014-8632 affects Mozilla Firefox versions prior to 34.0.
4
Which versions of SeaMonkey are affected by CVE-2014-8632?
CVE-2014-8632 affects SeaMonkey versions prior to 2.31.
5
What type of attack does CVE-2014-8632 enable?
CVE-2014-8632 allows remote attackers to bypass intended DOM object restrictions.