Lucene search

K
mozillaMozilla FoundationMFSA2009-32
HistoryJun 11, 2009 - 12:00 a.m.

JavaScript chrome privilege escalation β€” Mozilla

2009-06-1100:00:00
Mozilla Foundation
www.mozilla.org
35

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.019

Percentile

88.5%

Mozilla security researcher moz_bug_r_a4 reported a vulnerability which allows scripts from page content to run with elevated privileges. Using this vulnerability, an attacker could cause a chrome privileged object, such as the browser sidebar or the FeedWriter, to interact with web content in such a way that attacker controlled code may be executed with the object’s chrome privileges.

Affected configurations

Vulners
Node
mozillafirefoxRange<3.0.11
OR
mozillaseamonkeyRange<1.1.17
OR
mozillathunderbirdRange<2.0.0.22

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.019

Percentile

88.5%