Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The implementation of digital signatures for JAR files in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not prevent calls from unsigned JavaScript code to signed code, which allows remote attackers to bypass the Same Origin Policy and gain privileges via a crafted web site, a different vulnerability than CVE-2008-2801.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox未签名脚本安全策略绕过漏洞
Vulnerability Description
Mozilla Firefox 是一个自由的,开放源码的浏览器,适用于Windows、Linux 和 Mac OS X平台。 Mozilla Firefox 4.x至5版本的JAR文件数字签名的实现没有阻止未签名JavaScript代码对签名代码的调用,导致远程攻击者可以通过特制的网站绕过同源策略并获得特权。
CVSS Information
N/A
Vulnerability Type
N/A