CVE-2014-8636 describes a critical vulnerability in Mozilla Firefox and SeaMonkey versions prior to 35.0 and 2.32, respectively, stemming from improper interaction between XrayWrapper and DOM objects with named getters. This flaw allows remote attackers to execute arbitrary JavaScript code with chrome privileges. With a CVSS score of 7.5 (High) and an EPSS score indicating high exploitability, this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to full compromise of confidentiality, integrity, and availability. Exploit code, including a Metasploit module, is publicly available, and the vulnerability has garnered significant community discussion and media coverage, although it is not currently listed on the KEV catalog as actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 34.0.5CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
<= 2.31CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.