Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does not apply XPCNativeWrappers to scripts loaded from (1) file: URIs, (2) data: URIs, or (3) certain non-canonical chrome: URIs, which allows remote attackers to execute arbitrary code via vectors involving third-party add-ons.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox mozIJSSubScriptLoader.LoadScript 函数权限绕过漏洞
Vulnerability Description
Firefox是Mozilla所发布的开源WEB浏览器 mozIJSSubScriptLoader.LoadScript()函数中的漏洞可能导致绕过XPCNativeWrappers以Chrome权限执行任意代码。成功攻击要求安装了使用该函数的附加软件。
CVSS Information
N/A
Vulnerability Type
N/A