CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
AI Score
Confidence
High
EPSS
Percentile
86.0%
The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly select the context for script to run in, which allows remote attackers to bypass the Same Origin Policy or execute arbitrary JavaScript code with chrome privileges via a crafted web site.
Vendor | Product | Version | CPE |
---|---|---|---|
mozilla | firefox | 1.5.0.9 | cpe:/a:mozilla:firefox:1.5.0.9::: |
mozilla | firefox | 3.5.2 | cpe:/a:mozilla:firefox:3.5.2::: |
mozilla | firefox | 3.5.14 | cpe:/a:mozilla:firefox:3.5.14::: |
mozilla | firefox | 1.5.0.6 | cpe:/a:mozilla:firefox:1.5.0.6::: |
mozilla | firefox | 3.0.2 | cpe:/a:mozilla:firefox:3.0.2::: |
mozilla | firefox | 2.0.0.17 | cpe:/a:mozilla:firefox:2.0.0.17::: |
mozilla | firefox | 1.5.0.3 | cpe:/a:mozilla:firefox:1.5.0.3::: |
mozilla | firefox | 3.0.14 | cpe:/a:mozilla:firefox:3.0.14::: |
mozilla | firefox | 3.5.8 | cpe:/a:mozilla:firefox:3.5.8::: |
mozilla | firefox | 1.0.1 | cpe:/a:mozilla:firefox:1.0.1::: |
lists.opensuse.org/opensuse-security-announce/2011-08/msg00023.html
lists.opensuse.org/opensuse-security-announce/2011-08/msg00027.html
www.debian.org/security/2011/dsa-2295
www.debian.org/security/2011/dsa-2296
www.debian.org/security/2011/dsa-2297
www.mandriva.com/security/advisories?name=MDVSA-2011:127
www.mozilla.org/security/announce/2011/mfsa2011-30.html
www.redhat.com/support/errata/RHSA-2011-1164.html
bugzilla.mozilla.org/show_bug.cgi?id=614151
bugzilla.mozilla.org/show_bug.cgi?id=643450
bugzilla.mozilla.org/show_bug.cgi?id=650252
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14512