Description
The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not verify that content is valid JavaScript code, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted HTML document.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2010-1243 | The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not verify that content is valid JavaScript code, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted HTML document. |
Ubuntu USN |
USN-930-4 | Firefox and Xulrunner vulnerabilities |
Ubuntu USN |
USN-957-1 | Firefox and Xulrunner vulnerabilities |
Ubuntu USN |
USN-958-1 | Thunderbird vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T01:14:06.646Z
Reserved: 2010-03-30T00:00:00.000Z
Link: CVE-2010-1213
No data.
Status : Deferred
Published: 2010-07-30T20:30:01.583
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-1213
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN