Arbitrary code execution vulnerability in web console in Mozilla Firefox and Thunderbird via a crafted web site that injects this code and triggers an eval operation (Mac OS X)ID: oval:org.secpod.oval:def:6904 | Date: (C)2012-09-06 (M)2023-11-19 |
Class: VULNERABILITY | Family: macos |
The host is installed with Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, or Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and is prone to an arbitrary code execution vulnerability. A flaw is present in the applications, which fail to properly handle a crafted web site that injects this code and triggers an eval operation. Successful exploitation could allow attackers to execute arbitrary JavaScript code.
Platform: |
Apple Mac OS 14 |
Apple Mac OS 13 |
Apple Mac OS 12 |
Apple Mac OS 11 |
Apple Mac OS X 10.15 |
Apple Mac OS X 10.14 |
Apple Mac OS X 10.13 |
Apple Mac OS X 10.11 |
Apple Mac OS X 10.12 |
Product: |
Mozilla Firefox |
Mozilla Thunderbird |