Логотип exploitDog
bind:CVE-2009-3374
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2009-3374

Количество 6

Количество 6

ubuntu логотип

CVE-2009-3374

почти 16 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2009-3374

почти 16 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2009-3374

почти 16 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-3374

почти 16 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation i ...

CVSS2: 7.5
EPSS: Низкий
github логотип

GHSA-wr76-gg23-hq72

больше 3 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

EPSS: Низкий
oracle-oval логотип

ELSA-2009-1530

почти 16 лет назад

ELSA-2009-1530: firefox security update (CRITICAL)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2009-3374

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

CVSS2: 7.5
1%
Низкий
почти 16 лет назад
redhat логотип
CVE-2009-3374

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

CVSS2: 6.8
1%
Низкий
почти 16 лет назад
nvd логотип
CVE-2009-3374

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

CVSS2: 7.5
1%
Низкий
почти 16 лет назад
debian логотип
CVE-2009-3374

The XPCVariant::VariantDataToJS function in the XPCOM implementation i ...

CVSS2: 7.5
1%
Низкий
почти 16 лет назад
github логотип
GHSA-wr76-gg23-hq72

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

1%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2009-1530

ELSA-2009-1530: firefox security update (CRITICAL)

почти 16 лет назад

Уязвимостей на страницу