The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2009-10-29T14:00:00

Updated: 2017-09-18T12:57:01

Reserved: 2009-09-24T00:00:00


Link: CVE-2009-3374

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2009-10-29T14:30:00.937

Modified: 2017-09-19T01:29:35.563


Link: CVE-2009-3374

JSON object: View

cve-icon Redhat Information

No data.

CWE