TROYANOSYVIRUS
Voltar para CVEs

CVE-2010-1215

N/A

Descricao

Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrapper (aka SJOW) wrapper, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging "access to an object from the chrome scope."

Detalhes CVE

Pontuacao CVSS v3.1N/A
Publicado7/30/2010
Ultima modificacao4/29/2026
Fontenvd
Avistamentos honeypot0

Produtos afetados

mozilla:firefoxmozilla:thunderbird

Fraquezas (CWE)

CWE-94

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.