The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly select the context for script to run in, which allows remote attackers to bypass the Same Origin Policy or execute arbitrary JavaScript code with chrome privileges via a crafted web site.
CVSS Details
- CVSS 3.1 Base Score: 7.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade firefoxUpgrade xulrunner-develUpgrade xulrunner | Dec 1, 2016 | Aug 18, 2011 |
| Freebsd | — | Upgrade seamonkeyUpgrade linux-firefoxUpgrade firefoxUpgrade thunderbirdUpgrade linux-thunderbird | Dec 10, 2025 | Aug 16, 2011 |
| Gentoo Linux | — | Upgrade www-client/seamonkey.Upgrade www-client/firefox-bin.Upgrade www-client/firefox.Upgrade net-libs/xulrunner.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/mozilla-firefox.Upgrade dev-libs/nss.Upgrade mail-client/thunderbird.Upgrade www-client/icecat.Upgrade mail-client/thunderbird-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade net-libs/xulrunner-bin.Upgrade www-client/seamonkey-bin. | Oct 30, 2017 | Aug 18, 2011 |
| Mfsa2011 30 | — | Upgrade to Mozilla Firefox version 3.6.20 | Aug 19, 2011 | Aug 16, 2011 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 3.1.12 | Feb 22, 2012 | Aug 18, 2011 |
| Oracle_linux | — | Upgrade xulrunner-develUpgrade firefoxUpgrade xulrunner | Oct 16, 2024 | Aug 18, 2011 |
| Suse | — | Upgrade mozilla-xulrunner192-gnome-32bitUpgrade mozilla-xulrunner192-develUpgrade MozillaFirefoxUpgrade MozillaFirefox-translationsUpgrade mozilla-xulrunner192-translationsUpgrade mozilla-xulrunner192-gnomeUpgrade mozilla-xulrunner192-32bitUpgrade mozilla-xulrunner192Upgrade MozillaFirefox-develUpgrade mozilla-xulrunner192-x86Upgrade mozilla-xulrunner192-translations-32bit | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade firefoxUpgrade thunderbirdUpgrade xulrunner-1.9.2 | Nov 8, 2024 | Aug 18, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub