cbcvebase.
CVE-2009-2472
published 2009-07-22

CVE-2009-2472: Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the…

PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.24%
81.0th percentile
Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."

Affected

10 ranges
VendorProductVersion rangeFixed in
fedoraprojectfedora
mozillafirefox< 3.0.123.0.12
opensuseopensuse
opensuseopensuse
suselinux_enterprise_debuginfo
suselinux_enterprise_debuginfo
suselinux_enterprise_desktop
suselinux_enterprise_desktop
suselinux_enterprise_server
suselinux_enterprise_server

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.