CVE
- Id
- 39907
- CVE No.
- CVE-2009-2472
- Status
- Candidate
- Description
- Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."
- Phase
- Assigned (20090715)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
438507 | 39907 | CVE-2009-2472 | CONFIRM:http://www.mozilla.org/security/announce/2009/mfsa2009-40.html | View |
438508 | 39907 | CVE-2009-2472 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=479288 | View |
438509 | 39907 | CVE-2009-2472 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=481434 | View |
438510 | 39907 | CVE-2009-2472 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=497102 | View |
438511 | 39907 | CVE-2009-2472 | FEDORA:FEDORA-2009-7961 | View |
438512 | 39907 | CVE-2009-2472 | URL:https://www.redhat.com/archives/fedora-package-announce/2009-July/msg01032.html | View |
438513 | 39907 | CVE-2009-2472 | REDHAT:RHSA-2009:1162 | View |
438514 | 39907 | CVE-2009-2472 | URL:http://rhn.redhat.com/errata/RHSA-2009-1162.html | View |
438515 | 39907 | CVE-2009-2472 | SUNALERT:265068 | View |
438516 | 39907 | CVE-2009-2472 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-265068-1 | View |
438517 | 39907 | CVE-2009-2472 | SUNALERT:1020800 | View |
438518 | 39907 | CVE-2009-2472 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020800.1-1 | View |
438519 | 39907 | CVE-2009-2472 | SUSE:SUSE-SA:2009:042 | View |
438520 | 39907 | CVE-2009-2472 | URL:http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00002.html | View |
438521 | 39907 | CVE-2009-2472 | SUSE:SUSE-SA:2009:039 | View |
438522 | 39907 | CVE-2009-2472 | URL:http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00005.html | View |
438523 | 39907 | CVE-2009-2472 | BID:35758 | View |
438524 | 39907 | CVE-2009-2472 | URL:http://www.securityfocus.com/bid/35758 | View |
438525 | 39907 | CVE-2009-2472 | OVAL:oval:org.mitre.oval:def:9497 | View |
438526 | 39907 | CVE-2009-2472 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9497 | View |
438527 | 39907 | CVE-2009-2472 | SECUNIA:35914 | View |
438528 | 39907 | CVE-2009-2472 | URL:http://secunia.com/advisories/35914 | View |
438529 | 39907 | CVE-2009-2472 | SECUNIA:35944 | View |
438530 | 39907 | CVE-2009-2472 | URL:http://secunia.com/advisories/35944 | View |
438531 | 39907 | CVE-2009-2472 | SECUNIA:36145 | View |
438532 | 39907 | CVE-2009-2472 | URL:http://secunia.com/advisories/36145 | View |
438533 | 39907 | CVE-2009-2472 | SECUNIA:36005 | View |
438534 | 39907 | CVE-2009-2472 | URL:http://secunia.com/advisories/36005 | View |
438535 | 39907 | CVE-2009-2472 | VUPEN:ADV-2009-1972 | View |
438536 | 39907 | CVE-2009-2472 | URL:http://www.vupen.com/english/advisories/2009/1972 | View |
438537 | 39907 | CVE-2009-2472 | VUPEN:ADV-2009-2152 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
41002 | JVNDB-2009-002008 | Sun Java SE および OpenJDK の JMX におけるアクセス制限を回避される脆弱性 | Sun Java SE および OpenJDK の Java Management Extensions (JMX) 実装には、OpenType チェックを適切に実施しないため、アクセス制限を回避される脆弱性が存在します。 | CVE-2009-2476 | 39907 | 10 | http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002008.html | View |