CVE-2014-8632

Firefox < 34.0 and SeaMonkey < 2.31 - Improper Access Control via Structured-Clone and XrayWrapper Interaction

Title source: llm
STIX 2.1

Description

The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by leveraging property availability after XrayWrapper removal.

References (4)

Core 4
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201504-01
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1050340

Scores

EPSS 0.0021
EPSS Percentile 43.2%

Details

CWE
CWE-284
Status published
Products (2)
mozilla/firefox < 33.0
mozilla/seamonkey < 2.30
Published Dec 11, 2014
Tracked Since Feb 18, 2026