Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-3374

Опубликовано: 29 окт. 2009
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5

Описание

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

released

3.0.15+nobinonly-0ubuntu0.8.04.1
intrepid

released

3.0.15+nobinonly-0ubuntu0.8.10.1
jaunty

released

3.0.15+nobinonly-0ubuntu0.9.04.1
karmic

DNE

upstream

released

3.0.15

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

3.6.3+nobinonly-0ubuntu4
hardy

DNE

intrepid

DNE

jaunty

released

3.5.4+nobinonly-0ubuntu0.9.04.1
karmic

released

3.5.4+nobinonly-0ubuntu0.9.10.1
upstream

released

3.5.4

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

released

1.9.0.15+nobinonly-0ubuntu0.8.04.1
intrepid

released

1.9.0.15+nobinonly-0ubuntu0.8.10.1
jaunty

released

1.9.0.15+nobinonly-0ubuntu0.9.04.1
karmic

DNE

upstream

released

1.9.0.15

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

intrepid

DNE

jaunty

released

1.9.1.4+nobinonly-0ubuntu0.9.04.3
karmic

released

1.9.1.4+nobinonly-0ubuntu0.9.10.1
upstream

released

1.9.1.4

Показывать по

7.5 High

CVSS2

Связанные уязвимости

redhat
больше 15 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

nvd
больше 15 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

debian
больше 15 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation i ...

github
около 3 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

oracle-oval
больше 15 лет назад

ELSA-2009-1530: firefox security update (CRITICAL)

7.5 High

CVSS2