CVE

Id
28695  
CVE No.
CVE-2007-5338  
Status
Candidate  
Description
Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Script object to modify XPCNativeWrappers in a way that causes the script to be executed when a chrome action is performed.  
Phase
Assigned (20071010)  
Votes
None (candidate not yet proposed)  
Comments