Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6gg3-vvc7-gvjq

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are enabled, does not properly handle a Link HTTP header, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted web page, related to an incorrect security wrapper.

The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are enabled, does not properly handle a Link HTTP header, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted web page, related to an incorrect security wrapper.

EPSS

Процентиль: 81%
0.01528
Низкий

Дефекты

CWE-94

Связанные уязвимости

ubuntu
больше 16 лет назад

The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are enabled, does not properly handle a Link HTTP header, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted web page, related to an incorrect security wrapper.

nvd
больше 16 лет назад

The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are enabled, does not properly handle a Link HTTP header, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted web page, related to an incorrect security wrapper.

debian
больше 16 лет назад

The nsDocument::SetScriptGlobalObject function in content/base/src/nsD ...

EPSS

Процентиль: 81%
0.01528
Низкий

Дефекты

CWE-94