CVE-2014-8638

CVSS V2 Medium 6.8 CVSS V3 None
Description
The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.
Overview
  • CVE ID
  • CVE-2014-8638
  • Assigner
  • security@mozilla.org
  • Vulnerability Status
  • Modified
  • Published Version
  • 2015-01-14T11:59:07
  • Last Modified Date
  • 2017-09-08T01:29:26
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:mozilla:firefox_esr:31.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:mozilla:firefox_esr:31.1.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:mozilla:firefox_esr:31.1.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:mozilla:firefox_esr:31.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:mozilla:firefox_esr:31.3.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 1 OR 31.3.0
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 1 OR 34.0.5
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* 1 OR 2.31
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:N/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 6.8
  • Severity
  • MEDIUM
  • Exploitability Score
  • 8.6
  • Impact Score
  • 6.4
References
Reference URL Reference Tags
http://www.mozilla.org/security/announce/2014/mfsa2015-03.html Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1080987
http://secunia.com/advisories/62242
http://secunia.com/advisories/62250
http://www.securitytracker.com/id/1031533
http://secunia.com/advisories/62237
http://secunia.com/advisories/62446
http://secunia.com/advisories/62790
http://secunia.com/advisories/62657
http://www.debian.org/security/2015/dsa-3127
http://lists.opensuse.org/opensuse-updates/2015-01/msg00071.html
http://rhn.redhat.com/errata/RHSA-2015-0046.html
http://www.debian.org/security/2015/dsa-3132
http://www.ubuntu.com/usn/USN-2460-1
http://rhn.redhat.com/errata/RHSA-2015-0047.html
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00014.html
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00032.html
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00033.html
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00036.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
https://security.gentoo.org/glsa/201504-01
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
http://www.securitytracker.com/id/1031534
http://www.securityfocus.com/bid/72047
http://secunia.com/advisories/62418
http://secunia.com/advisories/62316
http://secunia.com/advisories/62315
http://secunia.com/advisories/62313
http://secunia.com/advisories/62304
http://secunia.com/advisories/62293
http://secunia.com/advisories/62283
http://secunia.com/advisories/62274
http://secunia.com/advisories/62273
http://secunia.com/advisories/62259
http://secunia.com/advisories/62253
http://linux.oracle.com/errata/ELSA-2015-0047.html
http://linux.oracle.com/errata/ELSA-2015-0046.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/99958
History
Created Old Value New Value Data Type Notes
2022-05-10 08:39:46 Added to TrackCVE
2022-12-02 03:06:50 2015-01-14T11:59Z 2015-01-14T11:59:07 CVE Published Date updated
2022-12-02 03:06:50 2017-09-08T01:29:26 CVE Modified Date updated
2022-12-02 03:06:50 Modified Vulnerability Status updated