CVE-2014-8636

EXPLOITED

Mozilla Firefox <35.0 - XSS

Title source: llm

Description

The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named getter, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via unspecified vectors.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/36480

References (19)

Scores

EPSS 0.8361
EPSS Percentile 99.3%

Details

VulnCheck KEV 2017-01-09
CWE
CWE-94
Status published
Products (2)
mozilla/firefox < 34.0.5
mozilla/seamonkey < 2.31
Published Jan 14, 2015
Tracked Since Feb 18, 2026