CVE-2009-4102
29.11.2009, 13:08
Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.Enginsight
Vendor | Product | Version |
---|---|---|
sage.mozdev | sage | 𝑥 ≤ 1.4.3 |
sage.mozdev | sage | 1.3.8 |
mozilla | firefox | * |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References