CVE-2009-0354

Mozilla Firefox <3.0.6 - XSS

Title source: llm

Description

Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.

Scores

EPSS 0.0079
EPSS Percentile 73.6%

Classification

CWE
CWE-79
Status published

Affected Products (10)

mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
n/a/n/a

Timeline

Published Feb 04, 2009
Tracked Since Feb 18, 2026