CVE Vulnerabilities

CVE-2009-3374

Published: Oct 29, 2009 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to doubly-wrapped objects.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 3.0-beta5 (including) 3.0-beta5 (including)
Firefox Mozilla 3.0.1 (including) 3.0.1 (including)
Firefox Mozilla 3.0.2 (including) 3.0.2 (including)
Firefox Mozilla 3.0.3 (including) 3.0.3 (including)
Firefox Mozilla 3.0.4 (including) 3.0.4 (including)
Firefox Mozilla 3.0.5 (including) 3.0.5 (including)
Firefox Mozilla 3.0.6 (including) 3.0.6 (including)
Firefox Mozilla 3.0.7 (including) 3.0.7 (including)
Firefox Mozilla 3.0.8 (including) 3.0.8 (including)
Firefox Mozilla 3.0.9 (including) 3.0.9 (including)
Firefox Mozilla 3.0.10 (including) 3.0.10 (including)
Firefox Mozilla 3.0.11 (including) 3.0.11 (including)
Firefox Mozilla 3.0.12 (including) 3.0.12 (including)
Firefox Mozilla 3.0.13 (including) 3.0.13 (including)
Firefox Mozilla 3.5.1 (including) 3.5.1 (including)
Firefox Mozilla 3.5.2 (including) 3.5.2 (including)
Firefox Mozilla 3.5.3 (including) 3.5.3 (including)
Red Hat Enterprise Linux 4 RedHat firefox-0:3.0.15-3.el4 *
Red Hat Enterprise Linux 4 RedHat nspr-0:4.7.6-1.el4_8 *
Red Hat Enterprise Linux 5 RedHat firefox-0:3.0.15-3.el5_4 *
Red Hat Enterprise Linux 5 RedHat nspr-0:4.7.6-1.el5_4 *
Red Hat Enterprise Linux 5 RedHat xulrunner-0:1.9.0.15-3.el5_4 *
Firefox-3.0 Ubuntu hardy *
Firefox-3.0 Ubuntu intrepid *
Firefox-3.0 Ubuntu jaunty *
Firefox-3.0 Ubuntu upstream *
Firefox-3.5 Ubuntu jaunty *
Firefox-3.5 Ubuntu karmic *
Firefox-3.5 Ubuntu upstream *
Xulrunner-1.9 Ubuntu hardy *
Xulrunner-1.9 Ubuntu intrepid *
Xulrunner-1.9 Ubuntu jaunty *
Xulrunner-1.9 Ubuntu upstream *
Xulrunner-1.9.1 Ubuntu jaunty *
Xulrunner-1.9.1 Ubuntu karmic *
Xulrunner-1.9.1 Ubuntu upstream *

References