CVE-2014-8643

Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging access to the GMP process, as demonstrated by the OpenH264 plugin's process.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:19

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00014.html - () http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00014.html -
References () http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00002.html - () http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00002.html -
References () http://secunia.com/advisories/62253 - () http://secunia.com/advisories/62253 -
References () http://secunia.com/advisories/62446 - () http://secunia.com/advisories/62446 -
References () http://www.mozilla.org/security/announce/2014/mfsa2015-07.html - Vendor Advisory () http://www.mozilla.org/security/announce/2014/mfsa2015-07.html - Vendor Advisory
References () http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html - () http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html -
References () http://www.securityfocus.com/bid/72043 - () http://www.securityfocus.com/bid/72043 -
References () http://www.securitytracker.com/id/1031533 - () http://www.securitytracker.com/id/1031533 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1117140 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1117140 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/99962 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/99962 -

Information

Published : 2015-01-14 11:59

Updated : 2024-11-21 02:19


NVD link : CVE-2014-8643

Mitre link : CVE-2014-8643

CVE.ORG link : CVE-2014-8643


JSON object : View

Products Affected

opensuse

  • opensuse

mozilla

  • firefox

microsoft

  • windows
CWE
CWE-264

Permissions, Privileges, and Access Controls