CVE-2009-2472
published 2009-07-22CVE-2009-2472: Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.24%
81.0th percentile
Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| mozilla | firefox | < 3.0.12 | 3.0.12 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_debuginfo | — | — |
| suse | linux_enterprise_debuginfo | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xwvm-8xx6-229v: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-2472 [MEDIUM] CWE-79 GHSA-xwvm-8xx6-229v: Mozilla Firefox before 3
Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-07-22·CVSS 10.0
CVE-2009-2462 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Several flaws were discovered in the Firefox browser and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-2462,
CVE-2009-2463, CVE-2009-2464, CVE-2009-2465, CVE-2009-2466, CVE-2009-2469)
Attila Suszter discovered a flaw in the way Firefox processed Flash content.
If a user were tricked into viewing and navigating within a specially
crafted Flash object, a remote attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2009-2467)
It was discovere
Red Hat
Mozilla multiple cross origin wrapper bypasses
vendor_redhat·2009-07-21·CVSS 4.3
CVE-2009-2472 [MEDIUM] Mozilla multiple cross origin wrapper bypasses
Mozilla multiple cross origin wrapper bypasses
Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-08/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2009-1162.htmlhttp://secunia.com/advisories/35914http://secunia.com/advisories/35944http://secunia.com/advisories/36005http://secunia.com/advisories/36145http://sunsolve.sun.com/search/document.do?assetkey=1-26-265068-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020800.1-1http://www.mozilla.org/security/announce/2009/mfsa2009-40.htmlhttp://www.securityfocus.com/bid/35758http://www.vupen.com/english/advisories/2009/1972http://www.vupen.com/english/advisories/2009/2152https://bugzilla.mozilla.org/show_bug.cgi?id=479288https://bugzilla.mozilla.org/show_bug.cgi?id=481434https://bugzilla.mozilla.org/show_bug.cgi?id=497102https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9497https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-08/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2009-1162.htmlhttp://secunia.com/advisories/35914http://secunia.com/advisories/35944http://secunia.com/advisories/36005http://secunia.com/advisories/36145http://sunsolve.sun.com/search/document.do?assetkey=1-26-265068-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020800.1-1http://www.mozilla.org/security/announce/2009/mfsa2009-40.htmlhttp://www.securityfocus.com/bid/35758http://www.vupen.com/english/advisories/2009/1972http://www.vupen.com/english/advisories/2009/2152https://bugzilla.mozilla.org/show_bug.cgi?id=479288https://bugzilla.mozilla.org/show_bug.cgi?id=481434https://bugzilla.mozilla.org/show_bug.cgi?id=497102https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9497https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01032.html
2009-07-22
Published