Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2009-3374
StatusUNKNOWN
DescriptionThe XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."
SeverityHigh
CVSS score7,5
CVSS vector(AV:N/AC:L/Au:N/C:P/I:P/A:P)
PhaseASSIGNED (21.08.2010)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3374
ReferencesCONFIRM : http://www.mozilla.org/security/announce/2009/mfsa...
 CONFIRM : https://bugzilla.mozilla.org/show_bug.cgi?id=505988
 MANDRIVA : MDVSA-2009:294
 OVAL : oval:org.mitre.oval:def:6565
 OVAL : oval:org.mitre.oval:def:9789
 SUNALERT : 272909
 VUPEN : ADV-2009-3334
SecurityVulns:Mozilla Firefox / Seamonkey multiple security vulnerabilities

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server