CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
88.7%
Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to execute arbitrary JavaScript with chrome privileges via vectors involving an object, the FeedWriter, and the BrowserFeedWriter.
Vendor | Product | Version | CPE |
---|---|---|---|
mozilla | firefox | 1.5.0.9 | cpe:/a:mozilla:firefox:1.5.0.9::: |
mozilla | firefox | 2.0+.6 | cpe:/a:mozilla:firefox:2.0+.6::: |
mozilla | firefox | 1.5.0.6 | cpe:/a:mozilla:firefox:1.5.0.6::: |
mozilla | firefox | 2.0 | cpe:/a:mozilla:firefox:2.0:beta1:: |
mozilla | firefox | 3.0.2 | cpe:/a:mozilla:firefox:3.0.2::: |
mozilla | firefox | 2.0.0.17 | cpe:/a:mozilla:firefox:2.0.0.17::: |
mozilla | firefox | 1.5.0.3 | cpe:/a:mozilla:firefox:1.5.0.3::: |
mozilla | firefox | 0.9.1 | cpe:/a:mozilla:firefox:0.9.1::: |
mozilla | firefox | 1.0.1 | cpe:/a:mozilla:firefox:1.0.1::: |
mozilla | firefox | 1.0.4 | cpe:/a:mozilla:firefox:1.0.4::: |
secunia.com/advisories/36670
secunia.com/advisories/36671
secunia.com/advisories/36757
secunia.com/advisories/37098
www.debian.org/security/2009/dsa-1886
www.mozilla.org/security/announce/2009/mfsa2009-51.html
www.novell.com/linux/security/advisories/2009_48_firefox.html
www.redhat.com/support/errata/RHSA-2009-1430.html
www.securityfocus.com/bid/36343
www.securitytracker.com/id?1022873
bugzilla.mozilla.org/show_bug.cgi?id=454363
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10390
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6250