oval:org.mitre.oval:def:12532
Definition Id: oval:org.mitre.oval:def:12532 | |||
Oval ID: | oval:org.mitre.oval:def:12532 | ||
Title: | Remote code execution vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 through ParanoidFragmentSink protection mechanism | ||
Description: | The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a chrome document, which makes it easier for remote attackers to execute arbitrary JavaScript with chrome privileges via a javascript: URI in input to an extension, as demonstrated by a javascript:alert sequence in (1) the HREF attribute of an A element or (2) the ACTION attribute of a FORM element. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-1585 | Version: | 21 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows XP | Product(s): | Mozilla Firefox Mozilla Thunderbird Mozilla SeaMonkey |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:6372 | |||
Oval ID: | oval:org.mitre.oval:def:6372 | ||
Title: | Mozilla Seamonkey is installed | ||
Description: | The installed browser on the system is Mozilla Seamonkey. | ||
Family: | windows | Class: | inventory |
Reference(s): | cpe:/a:mozilla:seamonkey | Version: | 11 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows 8 Microsoft Windows Server 2012 | Product(s): | Mozilla SeaMonkey |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:12532 |
Definition Id: oval:org.mitre.oval:def:22093 | |||
Oval ID: | oval:org.mitre.oval:def:22093 | ||
Title: | Mozilla Thunderbird Mainline release is installed | ||
Description: | The installed e-mail and news client on the system is Mozilla Thunderbird Mainline release | ||
Family: | windows | Class: | inventory |
Reference(s): | cpe:/a:mozilla:thunderbird | Version: | 9 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows 8 Microsoft Windows Server 2012 | Product(s): | Mozilla Thunderbird |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:12532 |
Definition Id: oval:org.mitre.oval:def:22259 | |||
Oval ID: | oval:org.mitre.oval:def:22259 | ||
Title: | Mozilla Firefox Mainline release is installed | ||
Description: | The browser installed on the system is Mozilla Firefox Mainline release | ||
Family: | windows | Class: | inventory |
Reference(s): | cpe:/a:mozilla:firefox | Version: | 9 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows 8 Microsoft Windows Server 2012 | Product(s): | Mozilla Firefox |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:12532 |