CVE-2009-0354
Mozilla Firefox <3.0.6 - XSS
Title source: llmDescription
Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.
References (18)
Scores
EPSS
0.0079
EPSS Percentile
73.6%
Classification
CWE
CWE-79
Status
published
Affected Products (10)
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
n/a/n/a
Timeline
Published
Feb 04, 2009
Tracked Since
Feb 18, 2026