The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are enabled, does not properly handle a Link HTTP header, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted web page, related to an incorrect security wrapper.
CVSS Details
- CVSS 3.1 Base Score: 8.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/seamonkey.Upgrade mail-client/thunderbird-bin.Upgrade dev-libs/nss.Upgrade net-libs/xulrunner.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/firefox-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/icecat.Upgrade www-client/firefox.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/thunderbird.Upgrade net-libs/xulrunner-bin.Upgrade www-client/seamonkey-bin. | Oct 30, 2017 | Aug 4, 2009 |
| Mfsa2009 46 | — | Upgrade to Mozilla Firefox version 3.5.2 | Jun 14, 2012 | Aug 4, 2009 |
| Ubuntu | — | Upgrade xulrunner-1.9.1 | Nov 19, 2024 | Aug 4, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub