Back

MEDIUM

Mozilla recursive eval call causes confirm dialog to evaluate to true (MFSA 2011-02)

Published Mar 2, 2011

Description

Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, does not properly handle certain recursive eval calls, which makes it easier for remote attackers to force a user to respond positively to a dialog question, as demonstrated by a question about granting privileges.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 2, 2011
Updated Aug 6, 2024
Reserved Dec 21, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Mar 1, 2011