Vulnerability Database

289,689

Total vulnerabilities in the database

CVE-2014-8639

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.

  • Published: Jan 14, 2015
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-8639
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

No CWE or OWASP classifications available.

Software From Fixed in
mozilla / seamonkey - 2.31.x
mozilla / firefox - 34.0.5.x
mozilla / firefox_esr 31.3.0 31.3.0.x
mozilla / firefox_esr 31.1.1 31.1.1.x
mozilla / firefox_esr 31.1.0 31.1.0.x
mozilla / firefox_esr 31.2 31.2.x
mozilla / firefox_esr 31.0 31.0.x
mozilla / thunderbird - 31.3.0.x