The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2008-09-24T18:00:00
Updated: 2024-08-07T10:00:42.290Z
Reserved: 2008-09-12T00:00:00
Link: CVE-2008-4058
Vulnrichment
No data.
NVD
Status : Modified
Published: 2008-09-24T20:37:04.533
Modified: 2024-11-21T00:50:47.070
Link: CVE-2008-4058
Redhat