CVE-2009-2472 vulnerability in Mozilla and Other Products
Published on July 22, 2009
Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."
Products Associated with CVE-2009-2472
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2009-2472 are published in these products:
Exploit Probability
EPSS
0.70%
Percentile
71.80%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.