The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger, leading to unwrapping operations and calls to DOM methods on the unwrapped objects.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "firefox", "binary_version": "29.0+build1-0ubuntu0.14.04.2" }, { "binary_name": "firefox-dev", "binary_version": "29.0+build1-0ubuntu0.14.04.2" }, { "binary_name": "firefox-globalmenu", "binary_version": "29.0+build1-0ubuntu0.14.04.2" }, { "binary_name": "firefox-mozsymbols", "binary_version": "29.0+build1-0ubuntu0.14.04.2" }, { "binary_name": "firefox-testsuite", "binary_version": "29.0+build1-0ubuntu0.14.04.2" } ] }