Vulnerabilities (CVE)

Filtered by vendor Didier Ernotte Subscribe
Filtered by product Inforss
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-4101 2 Didier Ernotte, Mozilla 2 Inforss, Firefox 2023-12-10 9.3 HIGH N/A
infoRSS 1.1.4.2 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.