Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute arbitrary code via the (1) valueOf.call or (2) valueOf.apply methods of an XBL binding, or (3) "by inserting an XBL method into the DOM's document.body prototype chain."
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2006-04-14T10:00:00
Updated: 2024-08-07T17:19:49.542Z
Reserved: 2006-04-12T00:00:00
Link: CVE-2006-1733
Vulnrichment
No data.
NVD
Status : Modified
Published: 2006-04-14T10:02:00.000
Modified: 2024-11-21T00:09:37.193
Link: CVE-2006-1733
Redhat