CVE-2014-8639: Mozilla Firefox
Medium severity, CVSS 6.8. EPSS: 1.9% chance of exploitation in the next 30 days.
Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.
Affected products
- Mozilla Firefox: up to and including 34.0.5; version 31.0 only; version 31.1.0 only; version 31.1.1 only; version 31.3.0 only
- Mozilla Firefox ESR: version 31.2 only
- Mozilla Seamonkey: up to and including 2.31
- Mozilla Thunderbird: up to and including 31.3.0
Published 2015-01-14. Last modified 2026-06-17.