Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Didier Ernotte Subscribe
Filtered by product Inforss
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-4101 2 Didier Ernotte, Mozilla 2 Inforss, Firefox 2017-08-16 9.3 HIGH N/A
infoRSS 1.1.4.2 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.