CVE-2014-8638
Summary
| CVE | CVE-2014-8638 |
|---|---|
| State | PUBLISHED |
| Assigner | mozilla |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-01-14 11:59:07 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 31.0 | All | All | All |
| Application | Mozilla | Firefox | 31.1.0 | All | All | All |
| Application | Mozilla | Firefox | 31.1.1 | All | All | All |
| Application | Mozilla | Firefox | 31.3.0 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox Esr | 31.2 | All | All | All |
| Application | Mozilla | Seamonkey | All | All | All | All |
| Application | Mozilla | Thunderbird | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| openSUSE-SU-2015:0133-1: moderate: Security update for MozillaThunderbir | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Oracle Solaris Third Party Bulletin - April 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| [security-announce] openSUSE-SU-2015:0192-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Gentoo Security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Security Advisory SA62304 - Oracle Linux update for thunderbird - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA62253 - Mozilla Firefox Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| linux.oracle.com | ELSA-2015-0046 | af854a3a-2127-422b-91ae-364da2661108 | linux.oracle.com | |
| [security-announce] SUSE-SU-2015:0180-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security Advisory SA62237 - Debian update for iceweasel - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA62273 - Red Hat update for firefox - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA62316 - Mozilla SeaMonkey Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA62250 - Ubuntu update for firefox - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Mozilla Firefox/Thunderbird/SeaMonkey sendBeacon Cross-Site Request Forgery Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Security Advisory SA62293 - Oracle Linux update for firefox - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA62315 - Mozilla Thunderbird Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA62657 - SUSE update for MozillaThunderbird - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [security-announce] openSUSE-SU-2015:0077-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security Advisory SA62242 - Ubuntu update for ubufox - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [security-announce] SUSE-SU-2015:0171-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Request Forgery Attacks, and Obtain Potentially Sensitive Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Security Advisory SA62274 - Red Hat update for thunderbird - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| linux.oracle.com | ELSA-2015-0047 | af854a3a-2127-422b-91ae-364da2661108 | linux.oracle.com | |
| Security Advisory SA62313 - Mozilla Firefox ESR Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| sendBeacon requests lack an Origin header — Mozilla | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| Security Advisory SA62259 - Debian update for icedove - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| USN-2460-1: Thunderbird vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [security-announce] SUSE-SU-2015:0173-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security Advisory SA62283 - Ubuntu update for thunderbird - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Access Denied | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Mozilla Thunderbird Multiple Flaws Let Remote Users Execute Arbitrary Code, Conduct Cross-Site Request Forgery Attacks, and Conduct Session Fixation Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Debian -- Security Information -- DSA-3132-1 icedove | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Security Advisory SA62446 - Waterfox Firefox Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-3127-1 iceweasel | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [security-announce] openSUSE-SU-2015:1266-1: important: Mozilla (Firefox | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Security Advisory SA62790 - SUSE update for seamonkey - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.