NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
14206  CVE-2010-2763  The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted function.    4.3  Medium  2017-01-18  2011-07-18  View
14205  CVE-2010-2762  The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox 3.6.x before 3.6.9 and Thunderbird 3.1.x before 3.1.3 does not properly restrict objects at the end of scope chains, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to a chrome privileged object and a chain ending in an outer object.    6.8  Medium  2017-01-18  2011-07-18  View
3916  CVE-2008-4058  The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS.    7.5  High  2017-01-03  2013-07-27  View
3917  CVE-2008-4059  The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.    7.5  High  2017-01-03  2013-08-25  View
18108  CVE-2016-1760  The XPC Services API in LaunchServices in Apple iOS before 9.3 allows attackers to bypass intended event-handler restrictions and modify an arbitrary app"s events via a crafted app.    2.1  Low  2017-01-19  2016-12-02  View

Page 2585 of 17672, showing 5 records out of 88360 total, starting on record 12921, ending on 12925

Actions