Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox/Thunderbird/SeaMonkey chrome特权本地文件权限提升漏洞
Vulnerability Description
当它在同一个tab(来自chrome或者privileged-about:page)中被访问时,Mozilla Firefox 会把chrome特权赋予给一个文件:URI,这使得用户协助式远程攻击者更易于借助一个已保存到本地系统的文件中的恶意代码,来运行拥有chrome特权的Java脚本。
CVSS Information
N/A
Vulnerability Type
N/A