CVE-2009-4102
29.11.2009, 13:08
Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.Enginsight
| Vendor | Product | Version |
|---|---|---|
| sage.mozdev | sage | 𝑥 ≤ 1.4.3 |
| sage.mozdev | sage | 1.3.8 |
| mozilla | firefox | * |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References