CVE-2010-2762Mozilla Firefox vulnerability

CWE-2646 documents5 sources
Severity
6.8MEDIUMNVD
EPSS
1.7%
top 17.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 9
Latest updateMay 17

Description

The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox 3.6.x before 3.6.9 and Thunderbird 3.1.x before 3.1.3 does not properly restrict objects at the end of scope chains, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to a chrome privileged object and a chain ending in an outer object.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages2 packages

NVDmozilla/firefox7 versions+6
NVDmozilla/thunderbird3.1, 3.1.1, 3.1.2+2

🔴Vulnerability Details

1
GHSA
GHSA-hmgm-6jfp-c635: The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox 32022-05-17

📋Vendor Advisories

3
Ubuntu
Firefox and Xulrunner regression2010-09-16
Ubuntu
Firefox and Xulrunner vulnerabilities2010-09-08
Red Hat
Mozilla SJOW creates scope chains ending in outer object (MFSA 2010-59)2010-09-07

💬Community

1
Bugzilla
CVE-2010-2762 Mozilla SJOW creates scope chains ending in outer object (MFSA 2010-59)2010-09-03