Lucene search

K
mozillaMozilla FoundationMFSA2009-40
HistoryJul 21, 2009 - 12:00 a.m.

Multiple cross origin wrapper bypasses — Mozilla

2009-07-2100:00:00
Mozilla Foundation
www.mozilla.org
13

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

71.3%

Mozilla security researcher moz_bug_r_a4 reported a series of vulnerabilities in which objects that normally receive a XPCCrossOriginWrapper are constructed without the wrapper. This can lead to cases where JavaScript from one website may unsafely access properties of such an object which had been set by a different website. A malicious website could use this vulnerability to launch a XSS attack and run arbitrary JavaScript within the context of another site.

Affected configurations

Vulners
Node
mozillafirefoxRange<3.0.12
OR
mozillafirefoxRange<3.5
CPENameOperatorVersion
firefoxlt3.0.12
firefoxlt3.5

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

71.3%