CVE-2009-3374

EUVD-2009-3356
The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
3.0:beta5
mozillafirefox
3.0.1
mozillafirefox
3.0.2
mozillafirefox
3.0.3
mozillafirefox
3.0.4
mozillafirefox
3.0.5
mozillafirefox
3.0.6
mozillafirefox
3.0.7
mozillafirefox
3.0.8
mozillafirefox
3.0.9
mozillafirefox
3.0.10
mozillafirefox
3.0.11
mozillafirefox
3.0.12
mozillafirefox
3.0.13
mozillafirefox
3.5.1
mozillafirefox
3.5.2
mozillafirefox
3.5.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox-3.0
dapper
dne
hardy
Fixed 3.0.15+nobinonly-0ubuntu0.8.04.1
released
intrepid
Fixed 3.0.15+nobinonly-0ubuntu0.8.10.1
released
jaunty
Fixed 3.0.15+nobinonly-0ubuntu0.9.04.1
released
karmic
dne
firefox-3.5
dapper
dne
hardy
dne
intrepid
dne
jaunty
Fixed 3.5.4+nobinonly-0ubuntu0.9.04.1
released
karmic
Fixed 3.5.4+nobinonly-0ubuntu0.9.10.1
released
xulrunner-1.9
dapper
dne
hardy
Fixed 1.9.0.15+nobinonly-0ubuntu0.8.04.1
released
intrepid
Fixed 1.9.0.15+nobinonly-0ubuntu0.8.10.1
released
jaunty
Fixed 1.9.0.15+nobinonly-0ubuntu0.9.04.1
released
karmic
dne
xulrunner-1.9.1
dapper
dne
hardy
dne
intrepid
dne
jaunty
Fixed 1.9.1.4+nobinonly-0ubuntu0.9.04.3
released
karmic
Fixed 1.9.1.4+nobinonly-0ubuntu0.9.10.1
released
Common Weakness Enumeration