CVE-2014-8636: Code Injection
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named getter, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8636?
CVE-2014-8636 has a high severity rating due to its potential to allow remote code execution with chrome privileges.
How do I fix CVE-2014-8636?
To fix CVE-2014-8636, update to Mozilla Firefox version 35.0 or later, or SeaMonkey version 2.32 or later.
What versions are affected by CVE-2014-8636?
CVE-2014-8636 affects Firefox versions prior to 35.0 and SeaMonkey versions prior to 2.32.
What types of attacks are enabled by CVE-2014-8636?
CVE-2014-8636 enables remote attackers to execute arbitrary JavaScript code with elevated privileges.
Is there a workaround for CVE-2014-8636?
There is no known workaround for CVE-2014-8636; upgrading to a patched version is the only solution.