Lucene search

K
mozillaMozilla FoundationMFSA2011-52
HistoryNov 08, 2011 - 12:00 a.m.

Code execution via NoWaiverWrapper — Mozilla

2011-11-0800:00:00
Mozilla Foundation
www.mozilla.org
23

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.006

Percentile

79.5%

Mozilla security researcher moz_bug_r_a4 reported that an internal privilege check failed to respect the NoWaiverWrappers introduced with Firefox 4. This could result in elevated privilege being granted to web content.

Affected configurations

Vulners
Node
mozillafirefoxRange<8
OR
mozillaseamonkeyRange<2.5
OR
mozillathunderbirdRange<8

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.006

Percentile

79.5%