← Back

CVE-2010-1215

nvd nist
Published: Jul 30, 2010Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrapper (aka SJOW) wrapper, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging "access to an object from the chrome scope."

Affected (6)

2 products
Firefox
Thunderbird
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 3.6.1
Version 3.6.2
Version 3.6.3
Version 3.6.4
Version 3.6.6
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.1

Timeline

No history available yet.