Back

MEDIUM

mozilla: XMLDocument:: load() doesn't check nsIContentPolicy (MFSA 2010-24)

Published Apr 5, 2010

Description

The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 5, 2010
Updated Aug 7, 2024
Reserved Jan 6, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Mar 30, 2010