CVE-2010-2762

EUVD-2010-2766
The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox 3.6.x before 3.6.9 and Thunderbird 3.1.x before 3.1.3 does not properly restrict objects at the end of scope chains, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to a chrome privileged object and a chain ending in an outer object.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
3.6
mozillafirefox
3.6.2
mozillafirefox
3.6.3
mozillafirefox
3.6.4
mozillafirefox
3.6.6
mozillafirefox
3.6.7
mozillafirefox
3.6.8
mozillathunderbird
3.1
mozillathunderbird
3.1.1
mozillathunderbird
3.1.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
dapper
ignored
hardy
ignored
jaunty
dne
karmic
dne
lucid
Fixed 3.6.9+build1+nobinonly-0ubuntu0.10.04.1
released
firefox-3.0
dapper
dne
hardy
Fixed 3.6.9+build1+nobinonly-0ubuntu0.8.04.1
released
jaunty
Fixed 3.6.9+build1+nobinonly-0ubuntu0.9.04.1
released
karmic
dne
lucid
dne
firefox-3.5
dapper
dne
hardy
dne
jaunty
Fixed 3.5.12+build1+nobinonly-0ubuntu0.9.04.1
released
karmic
Fixed 3.6.9+build1+nobinonly-0ubuntu0.9.10.2
released
lucid
dne
thunderbird
dapper
dne
hardy
not-affected
jaunty
not-affected
karmic
not-affected
lucid
not-affected
xulrunner-1.9.2
dapper
dne
hardy
Fixed 1.9.2.9+build1+nobinonly-0ubuntu0.8.04.1
released
jaunty
Fixed 1.9.2.9+build1+nobinonly-0ubuntu0.9.04.1
released
karmic
Fixed 1.9.2.9+build1+nobinonly-0ubuntu0.9.10.1
released
lucid
Fixed 1.9.2.9+build1+nobinonly-0ubuntu0.10.04.1
released
Common Weakness Enumeration