HIGH · 7.1

CVE-2014-8643

Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging access to the GMP process, as demonstrated by the OpenH...

Vulnerability Description

Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging access to the GMP process, as demonstrated by the OpenH264 plugin's process.

CVSS Score

7.1

HIGH

AV:N/AC:M/Au:N/C:N/I:C/A:N
Confidentiality
NONE
Integrity
COMPLETE
Availability
NONE

Affected Products

VendorProductVersions
OpensuseOpensuse13.1
MozillaFirefox<= 34.0.5
MicrosoftWindowsAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-8643?

CVE-2014-8643 is a vulnerability with a CVSS score of 7.1 (HIGH). Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging access to the GMP process, as demonstrated by the OpenH...

How severe is CVE-2014-8643?

CVE-2014-8643 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-8643?

Check the references section above for vendor advisories and patch information. Affected products include: Opensuse Opensuse, Mozilla Firefox, Microsoft Windows.