Уязвимость обхода ограничений доступа в Mozilla Firefox, Thunderbird и SeaMonkey через некорректное ограничение вызовов методов DOMWindowUtils
Описание
в Mozilla Firefox, Thunderbird и SeaMonkey обнаружена уязвимость, связанная с некорректным ограничением вызовов методов DOMWindowUtils
(также известных как nsDOMWindowUtils
). Эта уязвимость позволяет злоумышленникам обойти запланированные ограничения доступа, используя специально созданный JavaScript-код.
Затронутые версии ПО
- Mozilla Firefox до версии 16.0
- Mozilla Firefox ESR 10.x до версии 10.0.8
- Thunderbird до версии 16.0
- Thunderbird ESR 10.x до версии 10.0.8
- SeaMonkey до версии 2.13
Тип уязвимости
Обход ограничений доступа
Ссылки
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Issue TrackingVendor Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils) methods, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code.
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils) methods, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code.
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbi ...
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils) methods, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code.
EPSS
4.3 Medium
CVSS2