Описание
The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly select the context for script to run in, which allows remote attackers to bypass the Same Origin Policy or execute arbitrary JavaScript code with chrome privileges via a crafted web site.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | |
hardy | ignored | end of life |
lucid | released | 3.6.20+build1+nobinonly-0ubuntu0.10.04.1 |
maverick | released | 3.6.20+build1+nobinonly-0ubuntu0.10.10.1 |
natty | not-affected | |
oneiric | not-affected | |
precise | not-affected | |
quantal | not-affected | |
raring | not-affected | |
saucy | not-affected |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | ignored | end of life |
lucid | DNE | |
maverick | DNE | |
natty | DNE | |
oneiric | DNE | |
precise | DNE | |
quantal | DNE | |
raring | DNE | |
saucy | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | DNE | |
lucid | DNE | |
maverick | DNE | |
natty | DNE | |
oneiric | DNE | |
precise | DNE | |
quantal | DNE | |
raring | DNE | |
saucy | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | ignored | end of life |
lucid | ignored | end of life |
maverick | ignored | end of life |
natty | ignored | end of life |
oneiric | ignored | end of life |
precise | DNE | |
quantal | DNE | |
raring | DNE | |
saucy | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | |
hardy | ignored | end of life |
lucid | released | 3.1.12+build1+nobinonly-0ubuntu0.10.04.1 |
maverick | released | 3.1.12+build1+nobinonly-0ubuntu0.10.10.1 |
natty | released | 3.1.12+build1+nobinonly-0ubuntu0.11.04.1 |
oneiric | not-affected | |
precise | not-affected | |
quantal | not-affected | |
raring | not-affected | |
saucy | not-affected |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | ignored | end of life |
lucid | released | 1.9.2.20+build1+nobinonly-0ubuntu0.10.04.1 |
maverick | released | 1.9.2.20+build1+nobinonly-0ubuntu0.10.10.1 |
natty | not-affected | |
oneiric | DNE | |
precise | DNE | |
quantal | DNE | |
raring | DNE | |
saucy | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | DNE | |
lucid | DNE | |
maverick | DNE | |
natty | not-affected | |
oneiric | DNE | |
precise | DNE | |
quantal | DNE | |
raring | DNE | |
saucy | DNE |
Показывать по
EPSS
9.3 Critical
CVSS2
Связанные уязвимости
The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly select the context for script to run in, which allows remote attackers to bypass the Same Origin Policy or execute arbitrary JavaScript code with chrome privileges via a crafted web site.
The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly select the context for script to run in, which allows remote attackers to bypass the Same Origin Policy or execute arbitrary JavaScript code with chrome privileges via a crafted web site.
The event-management implementation in Mozilla Firefox before 3.6.20, ...
The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly select the context for script to run in, which allows remote attackers to bypass the Same Origin Policy or execute arbitrary JavaScript code with chrome privileges via a crafted web site.
EPSS
9.3 Critical
CVSS2