Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-2763
Description:The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted function.
Test IDs: 1.3.6.1.4.1.25623.1.0.68088   1.3.6.1.4.1.25623.1.0.801451   1.3.6.1.4.1.25623.1.0.67979  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-2763
Debian Security Information: DSA-2106 (Google Search)
http://www.debian.org/security/2010/dsa-2106
http://lists.fedoraproject.org/pipermail/package-announce/2010-September/047282.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12114
SuSE Security Announcement: SUSE-SA:2010:049 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00002.html
http://www.vupen.com/english/advisories/2010/2323
XForce ISS Database: firefox-sjow-security-bypass(61665)
https://exchange.xforce.ibmcloud.com/vulnerabilities/61665




© 1998-2025 E-Soft Inc. All rights reserved.