The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 does not perform the expected nsIContentPolicy checks during loading of content by XML documents, which allows attackers to bypass intended access restrictions via crafted content.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2010-04-05T17:00:00

Updated: 2017-09-18T12:57:01

Reserved: 2010-01-06T00:00:00


Link: CVE-2010-0182

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2010-04-05T17:30:00.657

Modified: 2018-10-30T16:25:58.530


Link: CVE-2010-0182

JSON object: View

cve-icon Redhat Information

No data.

CWE