CVE-2014-8636
Publication date 14 January 2015
Last updated 24 July 2024
Ubuntu priority
Description
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named getter, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via unspecified vectors.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| firefox | ||
| 14.04 LTS trusty |
Fixed 35.0+build3-0ubuntu0.14.04.2
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2458-1
- Firefox vulnerabilities
- 14 January 2015