CVE-2010-2762
Summary
| CVE | CVE-2010-2762 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-09-09 19:00:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox 3.6.x before 3.6.9 and Thunderbird 3.1.x before 3.1.3 does not properly restrict objects at the end of scope chains, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to a chrome privileged object and a chain ending in an outer object. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 3.6 | All | All | All |
| Application | Mozilla | Firefox | 3.6.2 | All | All | All |
| Application | Mozilla | Firefox | 3.6.3 | All | All | All |
| Application | Mozilla | Firefox | 3.6.4 | All | All | All |
| Application | Mozilla | Firefox | 3.6.6 | All | All | All |
| Application | Mozilla | Firefox | 3.6.7 | All | All | All |
| Application | Mozilla | Firefox | 3.6.8 | All | All | All |
| Application | Mozilla | Thunderbird | 3.1 | All | All | All |
| Application | Mozilla | Thunderbird | 3.1.1 | All | All | All |
| Application | Mozilla | Thunderbird | 3.1.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [security-announce] SUSE Security Announcement: Mozilla Firefox (SUSE-SA | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Bug 584180 – SJOWs create scope chains ending in outer objects | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| ASA-2010-263 (RHSA-2010-0681) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| Security | af854a3a-2127-422b-91ae-364da2661108 | blogs.sun.com | |
| Mozilla Firefox and Thunderbird 'XPCSafeJSObjectWrapper' Chrome Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| MFSA 2010-59: SJOW creates scope chains ending in outer object | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Vendor Advisory |
| Oracle Solaris Firefox Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Support / Security / Advisories / / MDVSA-2010:173 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.