Aller au contenu
appaloosa scout logo main rounded
N/A

CVE-2010-1215

EN Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrapper (aka SJOW) wrapper, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging "access to an object from the chrome scope."

Apps suivies affectées

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
mozilla thunderbird Windows cpe:2.3:a:mozilla:thunderbird:3.1:*:*:*:*:*:*:*
Voir sur NVD ↗