CVE

Id
50916  
CVE No.
CVE-2011-3004  
Status
Candidate  
Description
The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior.  
Phase
Assigned (20110801)  
Votes
None (candidate not yet proposed)  
Comments