CVE-2014-8643: Mozilla Firefox

High severity, CVSS 7.1. EPSS: 1.5% chance of exploitation in the next 30 days.

Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging access to the GMP process, as demonstrated by the OpenH264 plugin's process.

Affected products

  • Mozilla Firefox: up to and including 34.0.5
  • Opensuse Opensuse: version 13.1 only; version 13.2 only

Published 2015-01-14. Last modified 2026-06-17.