CVE-2014-1589

CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 0.64 % (80th)
0.64% Progress
Affected Products 2
Advisories 3

Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary namespace, which allows remote attackers to bypass intended access restrictions via an XBL binding.

Weaknesses
CWE-284
Improper Access Control
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2014-12-11 11:59:02
(9 years ago)
Updated Date
2016-12-22 02:59:14
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 33.0 and prior versions cpe:2.3:a:mozilla:firefox <= 33.0
  Mozilla Seamonkey 2.30 and prior versions cpe:2.3:a:mozilla:seamonkey <= 2.30
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...