CVE-2014-8636
EXPLOITEDMozilla Firefox <35.0 - XSS
Title source: llmDescription
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named getter, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via unspecified vectors.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/36480
References (19)
Scores
EPSS
0.8361
EPSS Percentile
99.3%
Details
VulnCheck KEV
2017-01-09
CWE
CWE-94
Status
published
Products (2)
mozilla/firefox
< 34.0.5
mozilla/seamonkey
< 2.31
Published
Jan 14, 2015
Tracked Since
Feb 18, 2026