CVE-2009-3374Mozilla Firefox vulnerability

CWE-2646 documents5 sources
Severity
7.5HIGHNVD
EPSS
0.9%
top 24.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 29
Latest updateMay 2

Description

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDmozilla/firefox17 versions+16

Patches

🔴Vulnerability Details

1
GHSA
GHSA-wr76-gg23-hq72: The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 32022-05-02

📋Vendor Advisories

3
Ubuntu
Firefox and Xulrunner regression2009-11-11
Ubuntu
Firefox and Xulrunner vulnerabilities2009-10-31
Red Hat
XPCVariant:: VariantDataToJS()2009-10-27

💬Community

1
Bugzilla
CVE-2009-3374 Firefox chrome privilege escalation in XPCVariant::VariantDataToJS()2009-10-21