CVE-2014-8639: Mozilla Firefox

Medium severity, CVSS 6.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.

Affected products

  • Mozilla Firefox: up to and including 34.0.5; version 31.0 only; version 31.1.0 only; version 31.1.1 only; version 31.3.0 only
  • Mozilla Firefox ESR: version 31.2 only
  • Mozilla Seamonkey: up to and including 2.31
  • Mozilla Thunderbird: up to and including 31.3.0

Published 2015-01-14. Last modified 2026-06-17.