Definition
New Search
Mozilla Privilege Escalation via XBL.method.eval
oval:org.mitre.oval:def:1037
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8 Mozilla Suite before 1.7.13 and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using an eval in an XBL method binding (XBL.method.eval) to create Javascript functions that are compiled with extra privileges.
Family:
windows
Status:
ACCEPTED
Platform(s):
- Microsoft Windows XP
- Microsoft Windows Server 2003
- Microsoft Windows 2000
Class:
vulnerability
Reference(s):
- CVE-2006-1735
Product(s):
- mozilla