The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published: 2008-09-24T18:00:00
Updated: 2024-08-07T10:00:42.290Z
Reserved: 2008-09-12T00:00:00
Link: CVE-2008-4058

No data.

Status : Deferred
Published: 2008-09-24T20:37:04.533
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-4058
