Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-3374

Опубликовано: 29 окт. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

released

3.0.15+nobinonly-0ubuntu0.8.04.1
intrepid

released

3.0.15+nobinonly-0ubuntu0.8.10.1
jaunty

released

3.0.15+nobinonly-0ubuntu0.9.04.1
karmic

DNE

upstream

released

3.0.15

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

3.6.3+nobinonly-0ubuntu4
hardy

DNE

intrepid

DNE

jaunty

released

3.5.4+nobinonly-0ubuntu0.9.04.1
karmic

released

3.5.4+nobinonly-0ubuntu0.9.10.1
upstream

released

3.5.4

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

released

1.9.0.15+nobinonly-0ubuntu0.8.04.1
intrepid

released

1.9.0.15+nobinonly-0ubuntu0.8.10.1
jaunty

released

1.9.0.15+nobinonly-0ubuntu0.9.04.1
karmic

DNE

upstream

released

1.9.0.15

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

intrepid

DNE

jaunty

released

1.9.1.4+nobinonly-0ubuntu0.9.04.3
karmic

released

1.9.1.4+nobinonly-0ubuntu0.9.10.1
upstream

released

1.9.1.4

Показывать по

EPSS

Процентиль: 74%
0.00887
Низкий

7.5 High

CVSS2

Связанные уязвимости

redhat
почти 16 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

nvd
почти 16 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

debian
почти 16 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation i ...

github
больше 3 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

oracle-oval
почти 16 лет назад

ELSA-2009-1530: firefox security update (CRITICAL)

EPSS

Процентиль: 74%
0.00887
Низкий

7.5 High

CVSS2