10
CVSSv2

CVE-2009-2665

Published: 04/08/2009 Updated: 04/09/2009
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x prior to 3.5.2, when certain add-ons are enabled, does not properly handle a Link HTTP header, which allows remote malicious users to execute arbitrary JavaScript with chrome privileges via a crafted web page, related to an incorrect security wrapper.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.5

mozilla firefox 3.5.1

mozilla firefox 3.5.2

Vendor Advisories

Mozilla Foundation Security Advisory 2009-46 Chrome privilege escalation due to incorrectly cached wrapper Announced August 3, 2009 Reporter Wladimir Palant, moz_bug_r_a4 Impact Critical Products Firefox Fixed in ...