Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-2665

Опубликовано: 04 авг. 2009
Источник: ubuntu
Приоритет: medium
CVSS2: 10

Описание

The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are enabled, does not properly handle a Link HTTP header, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted web page, related to an incorrect security wrapper.

РелизСтатусПримечание
dapper

ignored

end of life
devel

not-affected

hardy

not-affected

intrepid

DNE

jaunty

DNE

karmic

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

not-affected

1.9.0.14
intrepid

not-affected

1.9.0.14
jaunty

not-affected

1.9.0.14
karmic

DNE

upstream

released

1.9.0.14

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

DNE

intrepid

DNE

jaunty

released

1.9.1.3+build1+nobinonly-0ubuntu0.9.04.2
karmic

not-affected

upstream

needs-triage

Показывать по

10 Critical

CVSS2

Связанные уязвимости

nvd
больше 16 лет назад

The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are enabled, does not properly handle a Link HTTP header, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted web page, related to an incorrect security wrapper.

debian
больше 16 лет назад

The nsDocument::SetScriptGlobalObject function in content/base/src/nsD ...

github
больше 3 лет назад

The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are enabled, does not properly handle a Link HTTP header, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted web page, related to an incorrect security wrapper.

10 Critical

CVSS2