Oval Definition:oval:org.mitre.oval:tst:121172
Comment:Mozilla Thunderbird ESR version is less than 10.0.9 and greater than or equal to 10.x
Type:file_testNamespace:windows
Check_Existence:at_least_one_existsCheck:all
State Operator:AND
References
Object:oval:org.mitre.oval:obj:30278
State:oval:org.mitre.oval:ste:32898
State:oval:org.mitre.oval:ste:33296
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:16786
V
Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.
2014-10-06
BACK