Lucene search

K
cveMozillaCVE-2014-8631
HistoryDec 11, 2014 - 11:59 a.m.

CVE-2014-8631

2014-12-1111:59:12
CWE-284
mozilla
web.nvd.nist.gov
38
cve-2014-8631
chrome object wrapper
cow
mozilla firefox
seamonkey
remote attackers
dom object restrictions

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

9

Confidence

High

EPSS

0.002

Percentile

64.9%

The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 supports native-interface passing, which allows remote attackers to bypass intended DOM object restrictions via a call to an unspecified method.

Affected configurations

Nvd
Node
mozillafirefoxRange33.0
OR
mozillaseamonkeyRange2.30
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

9

Confidence

High

EPSS

0.002

Percentile

64.9%