Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected window.location protection mechanism, which might allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors that are specific to each affected plugin.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade net-libs/xulrunner.Upgrade www-client/seamonkey.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/icecat.Upgrade mail-client/thunderbird-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade dev-libs/nss.Upgrade www-client/firefox.Upgrade www-client/mozilla-firefox.Upgrade www-client/firefox-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey-bin. | Oct 30, 2017 | Mar 25, 2010 |
| Mfsa2010 10 | — | Upgrade to Mozilla Firefox version 3.6.2 | Jun 14, 2012 | Mar 25, 2010 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade mozilla-xulrunner192-translations-32bitUpgrade mozilla-xulrunner192-x86Upgrade MozillaFirefox-translations-otherUpgrade mozilla-xulrunner192-gnome-32bitUpgrade mozilla-xulrunner192-translationsUpgrade mozilla-xulrunner192-32bitUpgrade mozilla-xulrunner192-develUpgrade mozilla-xulrunner192Upgrade MozillaFirefox-translationsUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-commonUpgrade mozilla-xulrunner192-gnome | Aug 9, 2024 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub