Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary namespace, which allows remote attackers to bypass intended access restrictions via an XBL binding.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 33.0.x |
| mozilla / seamonkey | - | 2.30.x |