Back

HIGH

security flaw

Published Oct 21, 2007

Description

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Script object to modify XPCNativeWrappers in a way that causes the script to be executed when a chrome action is performed.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (52)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 21, 2007
Updated Aug 7, 2024
Reserved Oct 10, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Oct 18, 2007