The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly select the context for script to run in, which allows remote attackers to bypass the Same Origin Policy or execute arbitrary JavaScript code with chrome privileges via a crafted web site.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2011-08-18T18:00:00

Updated: 2017-09-18T12:57:01

Reserved: 2011-08-01T00:00:00


Link: CVE-2011-2981

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2011-08-18T18:55:01.553

Modified: 2017-09-19T01:33:28.867


Link: CVE-2011-2981

JSON object: View

cve-icon Redhat Information

No data.

CWE