CVE-2009-4101

infoRSS 1.1.4.2 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
VendorProductVersion
didier_ernotteinforss
𝑥
≤ 1.1.4.2
didier_ernotteinforss
0.5
didier_ernotteinforss
0.7.7
didier_ernotteinforss
0.8.4
didier_ernotteinforss
0.8.7
didier_ernotteinforss
0.8.8.1
didier_ernotteinforss
0.8.8.2
didier_ernotteinforss
0.8.9
didier_ernotteinforss
0.8.9.1
didier_ernotteinforss
0.8.9.3
didier_ernotteinforss
0.8.9.4
didier_ernotteinforss
0.8.9.5
didier_ernotteinforss
0.9.0
didier_ernotteinforss
0.10.0
didier_ernotteinforss
0.10.1
didier_ernotteinforss
1.0.0
didier_ernotteinforss
1.1.0.1
didier_ernotteinforss
1.1.1
didier_ernotteinforss
1.1.2
didier_ernotteinforss
1.1.3
didier_ernotteinforss
1.1.4
didier_ernotteinforss
1.1.4.1
𝑥
= Vulnerable software versions