[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-3079Date: (C)2009-09-10   (M)2024-03-27


Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to execute arbitrary JavaScript with chrome privileges via vectors involving an object, the FeedWriter, and the BrowserFeedWriter.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1022873
BID-36343
SECUNIA-36670
BID-36671
SECUNIA-36757
SECUNIA-37098
DSA-1886
RHSA-2009:1430
SUSE-SA:2009:048
http://www.mozilla.org/security/announce/2009/mfsa2009-51.html
https://bugzilla.mozilla.org/show_bug.cgi?id=454363
oval:org.mitre.oval:def:10390
oval:org.mitre.oval:def:6250

CPE    90
cpe:/a:mozilla:firefox:1.5:beta2
cpe:/a:mozilla:firefox:1.5:beta1
cpe:/a:mozilla:firefox:3.5.1
cpe:/a:mozilla:firefox:3.5.2
...
CWE    1
CWE-94
OVAL    51
oval:org.secpod.oval:def:300538
oval:org.secpod.oval:def:101977
oval:org.secpod.oval:def:101573
oval:org.secpod.oval:def:102387
...

© SecPod Technologies