MEDIUM · 4.3

CVE-2009-2472

Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site ...

Vulnerability Description

Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
MozillaFirefox< 3.0.12
FedoraprojectFedora10
SuseLinux Enterprise Debuginfo10
OpensuseOpensuse11.0
SuseLinux Enterprise Desktop10
SuseLinux Enterprise Server10

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-2472?

CVE-2009-2472 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site ...

How severe is CVE-2009-2472?

CVE-2009-2472 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-2472?

Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Fedoraproject Fedora, Suse Linux Enterprise Debuginfo, Opensuse Opensuse, Suse Linux Enterprise Desktop.