« Volver al listado

CVE-2014-1526

Estado: ModificadaMedia (6.8)—

The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger, leading to unwrapping operations and calls to DOM methods on the unwrapped objects.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-1526",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "security@mozilla.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-04-30T10:49:04.880",
  "references": [
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132437.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-05/msg00010.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-05/msg00033.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "http://secunia.com/advisories/59866",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "http://www.mozilla.org/security/announce/2014/mfsa2014-47.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "http://www.securitytracker.com/id/1030163",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "http://www.securitytracker.com/id/1030164",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2185-1",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=988106",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "https://security.gentoo.org/glsa/201504-01",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@mozilla.org"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132437.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-05/msg00010.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-05/msg00033.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/59866",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mozilla.org/security/announce/2014/mfsa2014-47.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1030163",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1030164",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2185-1",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=988106",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/201504-01",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger, leading to unwrapping operations and calls to DOM methods on the unwrapped objects."
    },
    {
      "lang": "es",
      "value": "La implemenatción XrayWrapper en Mozilla Firefox anterior a 29.0 y SeaMonkey anterior a 2.26 permite a atacantes remotos asistidos por un usuario, evadir restricciones de acceso a creando un sitio web manipulado que es visitado usando el depurador, conduciendo a operaciones de desempaquetado y llamadas a métodos DOM en los objetos desempaquetados."
    }
  ],
  "lastModified": "2026-06-17T00:05:04.437",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22E1CD48-0EA1-446C-B475-40A858298C1E",
              "versionEndExcluding": "29.0"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33C546F7-EF68-452F-BD96-A3D1B267D321",
              "versionEndExcluding": "2.26"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D305F7A-D159-4716-AB26-5E38BB5CD991"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2076871-2E80-4605-A470-A41C1A8EC7EE"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F61F047-129C-41A6-8A27-FFCBB8563E91"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "815D70A8-47D3-459C-A32C-9FEACA0659D1"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFBF430B-0832-44B0-AA0E-BA9E467F7668"
            },
            {
              "criteria": "cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A10BC294-9196-425F-9FB0-B1625465B47F"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5991814D-CA77-4C25-90D2-DB542B17E0AD"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@mozilla.org"
}