296,594
Total vulnerabilities in the database
Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.
Software | From | Fixed in |
---|---|---|
mozilla / firefox | 3.0.4 | 3.0.4.x |
mozilla / firefox | 3.0.5 | 3.0.5.x |
mozilla / firefox | 3.0-beta2 | 3.0-beta2.x |
mozilla / firefox | 3.0.3 | 3.0.3.x |
mozilla / firefox | 3.0 | 3.0.x |
mozilla / firefox | 3.0.1 | 3.0.1.x |
mozilla / firefox | 3.0.2 | 3.0.2.x |
mozilla / firefox | 3.0-beta5 | 3.0-beta5.x |
mozilla / firefox | 3.0-alpha | 3.0-alpha.x |