CVE-2010-2762

The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox 3.6.x before 3.6.9 and Thunderbird 3.1.x before 3.1.3 does not properly restrict objects at the end of scope chains, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to a chrome privileged object and a chain ending in an outer object.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:3.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.6.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.6.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.6.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.6.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.6.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.6.8:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:mozilla:thunderbird:3.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:3.1.2:*:*:*:*:*:*:*

History

21 Nov 2024, 01:17

Type Values Removed Values Added
References () http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox - () http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefox -
References () http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00002.html - () http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00002.html -
References () http://secunia.com/advisories/42867 - () http://secunia.com/advisories/42867 -
References () http://support.avaya.com/css/P8/documents/100112690 - () http://support.avaya.com/css/P8/documents/100112690 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2010:173 - () http://www.mandriva.com/security/advisories?name=MDVSA-2010:173 -
References () http://www.mozilla.org/security/announce/2010/mfsa2010-59.html - Vendor Advisory () http://www.mozilla.org/security/announce/2010/mfsa2010-59.html - Vendor Advisory
References () http://www.securityfocus.com/bid/43092 - () http://www.securityfocus.com/bid/43092 -
References () http://www.vupen.com/english/advisories/2010/2323 - () http://www.vupen.com/english/advisories/2010/2323 -
References () http://www.vupen.com/english/advisories/2011/0061 - () http://www.vupen.com/english/advisories/2011/0061 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=584180 - () https://bugzilla.mozilla.org/show_bug.cgi?id=584180 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/61656 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/61656 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11492 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11492 -

Information

Published : 2010-09-09 19:00

Updated : 2024-11-21 01:17


NVD link : CVE-2010-2762

Mitre link : CVE-2010-2762

CVE.ORG link : CVE-2010-2762


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
CWE
CWE-264

Permissions, Privileges, and Access Controls