Upstream information
Description
The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects.SUSE information
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having important severity.
National Vulnerability Database | |
---|---|
Base Score | 7.8 |
Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Access Vector | Network |
Access Complexity | Low |
Authentication | None |
Confidentiality Impact | Complete |
Integrity Impact | None |
Availability Impact | None |
SUSE Security Advisories:
- SUSE-SR:2009:020, published Tue, 12 Jan 2010 10:00:00 +0000
SUSE Timeline for this CVE
CVE page created: Tue Jul 9 17:16:59 2013CVE page last modified: Tue Sep 10 15:10:55 2024