The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted function.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2010-09-09T18:00:00

Updated: 2017-09-18T12:57:01

Reserved: 2010-07-14T00:00:00


Link: CVE-2010-2763

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2010-09-09T19:00:02.313

Modified: 2017-09-19T01:31:07.220


Link: CVE-2010-2763

JSON object: View

cve-icon Redhat Information

No data.

CWE