Lucene search

K
cveRedhatCVE-2009-0354
HistoryFeb 04, 2009 - 7:30 p.m.

CVE-2009-0354

2009-02-0419:30:00
CWE-79
redhat
web.nvd.nist.gov
46
cve-2009-0354
cross-domain vulnerability
mozilla firefox
same origin policy
xss
remote code execution

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

8.4

Confidence

High

EPSS

0.003

Percentile

69.6%

Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.

Affected configurations

Nvd
Node
mozillafirefoxMatch3.0
OR
mozillafirefoxMatch3.0alpha
OR
mozillafirefoxMatch3.0beta2
OR
mozillafirefoxMatch3.0beta5
OR
mozillafirefoxMatch3.0.1
OR
mozillafirefoxMatch3.0.2
OR
mozillafirefoxMatch3.0.3
OR
mozillafirefoxMatch3.0.4
OR
mozillafirefoxMatch3.0.5
VendorProductVersionCPE
mozillafirefox3.0cpe:2.3:a:mozilla:firefox:3.0:*:*:*:*:*:*:*
mozillafirefox3.0cpe:2.3:a:mozilla:firefox:3.0:alpha:*:*:*:*:*:*
mozillafirefox3.0cpe:2.3:a:mozilla:firefox:3.0:beta2:*:*:*:*:*:*
mozillafirefox3.0cpe:2.3:a:mozilla:firefox:3.0:beta5:*:*:*:*:*:*
mozillafirefox3.0.1cpe:2.3:a:mozilla:firefox:3.0.1:*:*:*:*:*:*:*
mozillafirefox3.0.2cpe:2.3:a:mozilla:firefox:3.0.2:*:*:*:*:*:*:*
mozillafirefox3.0.3cpe:2.3:a:mozilla:firefox:3.0.3:*:*:*:*:*:*:*
mozillafirefox3.0.4cpe:2.3:a:mozilla:firefox:3.0.4:*:*:*:*:*:*:*
mozillafirefox3.0.5cpe:2.3:a:mozilla:firefox:3.0.5:*:*:*:*:*:*:*

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

8.4

Confidence

High

EPSS

0.003

Percentile

69.6%