Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | 4.0 | 7.0.x |
| mozilla / firefox | - | 3.6.24 |