DescriptionMozilla Firefox 1.5.x before 18.104.22.168 and 2.x before 22.214.171.124, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the same-origin policy and conduct cross-site scripting (XSS) and other attacks by using the addEventListener method to add an event listener for a site, which is executed in the context of that site.
Overall state of this security issue: Resolved
This issue is currently rated as having important severity.
|National Vulnerability Database|
- SUSE-SA:2007:036, published Wed, 27 Jun 2007 15:00:00 +0000