The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-07-22 11:30
Updated : 2017-09-18 18:29
NVD link : CVE-2009-2471
Mitre link : CVE-2009-2471
JSON object : View
CWE
Products Affected
mozilla
- firefox