CVE-2009-1841
CVE-2009-1841
js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://osvdb.org/55159http://rhn.redhat.com/errata/RHSA-2009-1096.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=479560https://bugzilla.redhat.com/show_bug.cgi?id=503583http://secunia.com/advisories/35331http://secunia.com/advisories/35415http://secunia.com/advisories/35428http://secunia.com/advisories/35431http://secunia.com/advisories/35439http://secunia.com/advisories/35440http://secunia.com/advisories/35468http://secunia.com/advisories/35536