|Description||Mozilla Firefox before 184.108.40.206, Thunderbird 220.127.116.11 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to execute arbitrary code via an XUL document that includes a script from a chrome: URI that points to a fastload file, related to this file's "privilege level."|
|Source||CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)|
|References||DSA-1607-1, DSA-1615-1, DSA-1621-1, DSA-1697-1|
The information below is based on the following data on fixed versions.