CVE-2014-1589

Mozilla Firefox <34.0 & SeaMonkey <2.31 - XSS

Title source: llm
STIX 2.1

Description

Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary namespace, which allows remote attackers to bypass intended access restrictions via an XBL binding.

References (4)

Core 4
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201504-01
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1043787

Scores

EPSS 0.0031
EPSS Percentile 53.9%

Details

CWE
CWE-284
Status published
Products (2)
mozilla/firefox < 33.0
mozilla/seamonkey < 2.30
Published Dec 11, 2014
Tracked Since Feb 18, 2026