Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not properly restrict the context of HTML markup and Cascading Style Sheets (CSS) token sequences, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted stylesheet.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox/SeaMonkey/Thunderbird Style Inspector 权限许可和访问控制漏洞
Vulnerability Description
Firefox是一款非常流行的开源WEB浏览器。 Mozilla Firefox 17.0之前版本和Firefox ESR 10.0.11之前的10.x版本中的Style Inspector中存在漏洞,该漏洞源于没有正确限制HTML标记的上下文和Cascading Style Sheets (CSS)令牌序列。用户协助的远程攻击者利用该漏洞通过特制的样式表单,以chrom权限执行任意JavaScript代码。
CVSS Information
N/A
Vulnerability Type
N/A