Security Advisory

CVE-2014-8632

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-12-11 11:00:00
Last updated 2024-08-06 13:26:02
Assigner mozilla
CVSS score not scored
State PUBLISHED

Description

The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by leveraging property availability after XrayWrapper removal.