CVE Vulnerabilities

CVE-2009-3374

Published: Oct 29, 2009 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to doubly-wrapped objects.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 3.0-beta5 (including) 3.0-beta5 (including)
Firefox Mozilla 3.0.1 (including) 3.0.1 (including)
Firefox Mozilla 3.0.2 (including) 3.0.2 (including)
Firefox Mozilla 3.0.3 (including) 3.0.3 (including)
Firefox Mozilla 3.0.4 (including) 3.0.4 (including)
Firefox Mozilla 3.0.5 (including) 3.0.5 (including)
Firefox Mozilla 3.0.6 (including) 3.0.6 (including)
Firefox Mozilla 3.0.7 (including) 3.0.7 (including)
Firefox Mozilla 3.0.8 (including) 3.0.8 (including)
Firefox Mozilla 3.0.9 (including) 3.0.9 (including)
Firefox Mozilla 3.0.10 (including) 3.0.10 (including)
Firefox Mozilla 3.0.11 (including) 3.0.11 (including)
Firefox Mozilla 3.0.12 (including) 3.0.12 (including)
Firefox Mozilla 3.0.13 (including) 3.0.13 (including)
Firefox Mozilla 3.5.1 (including) 3.5.1 (including)
Firefox Mozilla 3.5.2 (including) 3.5.2 (including)
Firefox Mozilla 3.5.3 (including) 3.5.3 (including)

References