EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to gain privileges via javascript that calls the valueOf method on objects that were created outside of the sandbox.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | 1.5-beta2 | 1.5-beta2.x |
| mozilla / thunderbird | 1.0.7 | 1.0.7.x |
| mozilla / firefox | 1.0.2 | 1.0.2.x |
| mozilla / firefox | 1.5-beta1 | 1.5-beta1.x |
| mozilla / firefox | 1.5 | 1.5.x |
| mozilla / firefox | 1.0.4 | 1.0.4.x |
| mozilla / firefox | 1.0.7 | 1.0.7.x |
| mozilla / thunderbird | 1.0 | 1.0.x |
| mozilla / thunderbird | 1.0.1 | 1.0.1.x |
| mozilla / thunderbird | 1.5-beta2 | 1.5-beta2.x |
| mozilla / thunderbird | 1.0.2 | 1.0.2.x |
| mozilla / firefox | 1.0 | 1.0.x |
| mozilla / thunderbird | 1.5 | 1.5.x |
| mozilla / firefox | 1.0.1 | 1.0.1.x |
| mozilla / firefox | preview_release | preview_release.x |
| mozilla / thunderbird | 1.0.4 | 1.0.4.x |
| mozilla / thunderbird | 1.0.3 | 1.0.3.x |
| mozilla / firefox | 1.0.3 | 1.0.3.x |
| mozilla / thunderbird | 1.0.6 | 1.0.6.x |
| mozilla / thunderbird | 1.0.5-beta | 1.0.5-beta.x |
| mozilla / thunderbird | 1.0.5 | 1.0.5.x |
| mozilla / firefox | 1.5.0.1 | 1.5.0.1.x |
| mozilla / firefox | 1.0.5 | 1.0.5.x |
| mozilla / firefox | 1.0.6 | 1.0.6.x |