4.3
CVSSv2

CVE-2010-2763

Published: 09/09/2010 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox prior to 3.5.12, Thunderbird prior to 3.0.7, and SeaMonkey prior to 2.0.7 does not properly restrict scripted functions, which allows remote malicious users to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted function.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla seamonkey 1.0.6

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0

mozilla seamonkey 1.1.11

mozilla seamonkey 1.1.19

mozilla seamonkey 1.1.2

mozilla seamonkey 1.1.9

mozilla seamonkey 1.1

mozilla seamonkey 2.0.2

mozilla seamonkey 2.0.3

mozilla seamonkey 2.0

mozilla seamonkey 2.0a1pre

mozilla seamonkey 1.0.1

mozilla seamonkey 1.0.8

mozilla seamonkey 1.0.9

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.13

mozilla seamonkey 1.1.3

mozilla seamonkey 1.1.4

mozilla seamonkey 1.5.0.10

mozilla seamonkey 2.0.4

mozilla seamonkey 2.0.5

mozilla seamonkey

mozilla seamonkey 1.0.4

mozilla seamonkey 1.0.5

mozilla seamonkey 1.1.10

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.17

mozilla seamonkey 1.1.18

mozilla seamonkey 1.1.7

mozilla seamonkey 1.1.8

mozilla seamonkey 2.0.1

mozilla seamonkey 1.0.2

mozilla seamonkey 1.0.3

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.15

mozilla seamonkey 1.1.5

mozilla seamonkey 1.1.6

mozilla seamonkey 1.5.0.8

mozilla seamonkey 1.5.0.9

mozilla thunderbird 3.0.5

mozilla thunderbird 3.0.3

mozilla thunderbird 2.0.0.19

mozilla thunderbird 2.0.0.12

mozilla thunderbird 2.0.0.14

mozilla thunderbird 2.0.0.17

mozilla thunderbird 1.5.0.8

mozilla thunderbird 1.5.2

mozilla thunderbird 1.5.0.1

mozilla thunderbird 1.5.0.10

mozilla thunderbird 1.0.6

mozilla thunderbird 1.0.7

mozilla thunderbird 1.0.1

mozilla thunderbird 0.7.2

mozilla thunderbird 0.2

mozilla thunderbird 0.5

mozilla thunderbird 0.6

mozilla thunderbird 3.0.4

mozilla thunderbird 3.0

mozilla thunderbird 2.0.0.5

mozilla thunderbird 2.0.0.4

mozilla thunderbird 2.0.0.22

mozilla thunderbird 2.0.0.9

mozilla thunderbird 1.5.1

mozilla thunderbird 1.5

mozilla thunderbird 1.5.0.11

mozilla thunderbird 1.5.0.2

mozilla thunderbird 1.5.0.12

mozilla thunderbird 1.0.8

mozilla thunderbird 1.0.2

mozilla thunderbird 0.7.3

mozilla thunderbird 0.7

mozilla thunderbird 0.3

mozilla thunderbird 0.4

mozilla thunderbird 3.0.1

mozilla thunderbird 3.0.2

mozilla thunderbird 2.0.0.3

mozilla thunderbird 2.0.0.2

mozilla thunderbird 2.0.0.21

mozilla thunderbird 2.0.0.16

mozilla thunderbird 2.0.0.18

mozilla thunderbird 1.5.0.9

mozilla thunderbird 1.5.0.6

mozilla thunderbird 1.5.0.7

mozilla thunderbird 1.5.0.14

mozilla thunderbird 1.0.5

mozilla thunderbird 1.0

mozilla thunderbird 0.9

mozilla thunderbird 0.1

mozilla thunderbird

mozilla thunderbird 2.0.0.1

mozilla thunderbird 2.0.0.0

mozilla thunderbird 2.0.0.8

mozilla thunderbird 2.0.0.7

mozilla thunderbird 2.0

mozilla thunderbird 2.0.0.23

mozilla thunderbird 2.0.0.6

mozilla thunderbird 1.5.0.3

mozilla thunderbird 1.5.0.4

mozilla thunderbird 1.5.0.5

mozilla thunderbird 1.5.0.13

mozilla thunderbird 1.0.3

mozilla thunderbird 1.0.4

mozilla thunderbird 0.7.1

mozilla thunderbird 0.8

mozilla firefox 3.5.4

mozilla firefox 3.5.5

mozilla firefox 3.5

mozilla firefox 3.0.17

mozilla firefox 3.0.10

mozilla firefox 3.0.9

mozilla firefox 3.0.8

mozilla firefox 3.0.1

mozilla firefox 3.0

mozilla firefox 2.0.0.17

mozilla firefox 2.0.0.10

mozilla firefox 2.0.0.6

mozilla firefox 2.0.0.5

mozilla firefox 1.5.0.5

mozilla firefox 1.5.0.2

mozilla firefox 1.5.3

mozilla firefox 1.5.4

mozilla firefox 1.5.8

mozilla firefox 1.5.7

mozilla firefox 1.0.5

mozilla firefox 1.0.4

mozilla firefox 3.5.6

mozilla firefox 3.5.7

mozilla firefox 3.0.16

mozilla firefox 3.0.15

mozilla firefox 3.0.7

mozilla firefox 3.0.6

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.12

mozilla firefox 2.0.0.16

mozilla firefox 2.0.0.11

mozilla firefox 2.0.0.4

mozilla firefox 2.0.0.3

mozilla firefox 1.5.0.3

mozilla firefox 1.5.0.11

mozilla firefox 1.5.1

mozilla firefox 1.5.2

mozilla firefox 1.5.6

mozilla firefox 1.5.5

mozilla firefox 1.0.7

mozilla firefox 1.0.6

mozilla firefox 3.5.2

mozilla firefox 3.5.3

mozilla firefox 3.5.9

mozilla firefox 3.5.8

mozilla firefox 3.0.12

mozilla firefox 3.0.11

mozilla firefox 3.0.3

mozilla firefox 3.0.2

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.9

mozilla firefox 2.0.0.7

mozilla firefox 2.0

mozilla firefox 2.0.0.18

mozilla firefox 1.5

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.10

mozilla firefox 1.5.0.7

mozilla firefox 1.0.3

mozilla firefox 1.0.2

mozilla firefox 3.5.1

mozilla firefox 3.5.10

mozilla firefox

mozilla firefox 3.0.14

mozilla firefox 3.0.13

mozilla firefox 3.0.5

mozilla firefox 3.0.4

mozilla firefox 2.0.0.19

mozilla firefox 2.0.0.20

mozilla firefox 2.0.0.15

mozilla firefox 2.0.0.13

mozilla firefox 2.0.0.2

mozilla firefox 2.0.0.1

mozilla firefox 1.5.0.12

mozilla firefox 1.5.0.1

mozilla firefox 1.5.0.8

mozilla firefox 1.5.0.9

mozilla firefox 1.5.0.6

mozilla firefox 1.0.1

mozilla firefox 1.0

mozilla firefox 1.0.8

Vendor Advisories

Thunderbird could be made to crash or possibly run programs as your login if it opened a specially crafted file or website ...
This update provides stability updates for Thunderbird ...
Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-2760, CVE-2010-3167, CVE-2010-3168 Implementation errors in XUL processing allow the execution of arbitrary code CVE-2010-2763 An implementation ...
Mozilla Foundation Security Advisory 2010-60 XSS using SJOW scripted function Announced September 7, 2010 Reporter moz_bug_r_a4 Impact High Products Firefox, SeaMonkey, Thunderbird Fixed in ...