Lucene search

K
cve[email protected]CVE-2009-2472
HistoryJul 22, 2009 - 6:30 p.m.

CVE-2009-2472

2009-07-2218:30:00
CWE-79
web.nvd.nist.gov
49
4
cve-2009-2472
mozilla firefox
xss
same origin policy
cross origin wrapper bypass
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

7.5 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.3%

Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a “cross origin wrapper bypass.”

Affected configurations

NVD
Node
mozillafirefoxRange<3.0.12
Node
fedoraprojectfedoraMatch10
Node
suselinux_enterprise_debuginfoMatch10sp2
OR
suselinux_enterprise_debuginfoMatch11-
OR
opensuseopensuseMatch11.0
OR
opensuseopensuseMatch11.1
OR
suselinux_enterprise_desktopMatch10sp2
OR
suselinux_enterprise_desktopMatch11-
OR
suselinux_enterprise_serverMatch10sp2
OR
suselinux_enterprise_serverMatch11-
CPENameOperatorVersion
mozilla:firefoxmozilla firefoxlt3.0.12

References

Social References

More

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

7.5 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.3%