Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-2665
HistoryAug 04, 2009 - 12:00 a.m.

CVE-2009-2665

2009-08-0400:00:00
ubuntu.com
ubuntu.com
12

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.014

Percentile

86.4%

The nsDocument::SetScriptGlobalObject function in
content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when
certain add-ons are enabled, does not properly handle a Link HTTP header,
which allows remote attackers to execute arbitrary JavaScript with chrome
privileges via a crafted web page, related to an incorrect security
wrapper.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu9.04noarchxulrunner-1.9.1< 1.9.1.3+build1+nobinonly-0ubuntu0.9.04.2UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.014

Percentile

86.4%