CVE Vulnerabilities

CVE-2009-3374

Published: Oct 29, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to doubly-wrapped objects.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla3.0-beta5 (including)3.0-beta5 (including)
FirefoxMozilla3.0.1 (including)3.0.1 (including)
FirefoxMozilla3.0.2 (including)3.0.2 (including)
FirefoxMozilla3.0.3 (including)3.0.3 (including)
FirefoxMozilla3.0.4 (including)3.0.4 (including)
FirefoxMozilla3.0.5 (including)3.0.5 (including)
FirefoxMozilla3.0.6 (including)3.0.6 (including)
FirefoxMozilla3.0.7 (including)3.0.7 (including)
FirefoxMozilla3.0.8 (including)3.0.8 (including)
FirefoxMozilla3.0.9 (including)3.0.9 (including)
FirefoxMozilla3.0.10 (including)3.0.10 (including)
FirefoxMozilla3.0.11 (including)3.0.11 (including)
FirefoxMozilla3.0.12 (including)3.0.12 (including)
FirefoxMozilla3.0.13 (including)3.0.13 (including)
FirefoxMozilla3.5.1 (including)3.5.1 (including)
FirefoxMozilla3.5.2 (including)3.5.2 (including)
FirefoxMozilla3.5.3 (including)3.5.3 (including)
Red Hat Enterprise Linux 4RedHatfirefox-0:3.0.15-3.el4*
Red Hat Enterprise Linux 4RedHatnspr-0:4.7.6-1.el4_8*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.0.15-3.el5_4*
Red Hat Enterprise Linux 5RedHatnspr-0:4.7.6-1.el5_4*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.0.15-3.el5_4*
Firefox-3.0Ubuntuhardy*
Firefox-3.0Ubuntuintrepid*
Firefox-3.0Ubuntujaunty*
Firefox-3.0Ubuntuupstream*
Firefox-3.5Ubuntujaunty*
Firefox-3.5Ubuntukarmic*
Firefox-3.5Ubuntuupstream*
Xulrunner-1.9Ubuntuhardy*
Xulrunner-1.9Ubuntuintrepid*
Xulrunner-1.9Ubuntujaunty*
Xulrunner-1.9Ubuntuupstream*
Xulrunner-1.9.1Ubuntujaunty*
Xulrunner-1.9.1Ubuntukarmic*
Xulrunner-1.9.1Ubuntuupstream*

References