Oval Definition:oval:org.mitre.oval:def:11527
Revision Date:2014-10-06Version:28
Title:Mozilla Firefox and Thunderbird Arbitrary code execution using SJOW and fast native function
Description:Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrapper (aka SJOW) wrapper, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging "access to an object from the chrome scope."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2010-1215
Platform(s):Microsoft Windows 2000
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Mozilla Firefox
Mozilla Thunderbird
Definition Synopsis
  • Check for vulnerable Firefox mainline
  • Mozilla Firefox Mainline release is installed
  • AND Check for vulnerable version
  • Mozilla Firefox Mainline version is 3.6.x before 3.6.7
  • OR Check for vulnerable Thunderbird Mainline
  • Mozilla Thunderbird Mainline release is installed
  • AND Mozilla Thunderbird 3.1.x before 3.1.1
  • BACK