« Volver al listado

CVE-2009-4102

Estado: ModificadaAlta (9.3)—

Sage v1.4.3 y anteriores extensiones para Firefox realiza ciertas operaciones con privilegios del chrome, lo que permite a atacantes remotos ejecutar comandos de su elección y realizar ataques ataques de secuencias de comandos a través de la etiqueta descripción de un feed RSS.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-4102",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-11-29T13:08:29.437",
  "references": [
    {
      "url": "http://forums.mozillazine.org/viewtopic.php?f=48&t=1603515&start=0",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN99203127/index.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2011-000070",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/37466",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.debian.org/security/2009/dsa-1951",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.net-security.org/secworld.php?id=8527",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/37120",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/3324",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54396",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://forums.mozillazine.org/viewtopic.php?f=48&t=1603515&start=0",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN99203127/index.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2011-000070",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/37466",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2009/dsa-1951",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.net-security.org/secworld.php?id=8527",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/37120",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/3324",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54396",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed."
    },
    {
      "lang": "es",
      "value": "Sage v1.4.3 y anteriores extensiones para Firefox realiza ciertas operaciones con privilegios del chrome, lo que permite a atacantes remotos ejecutar comandos de su elección y realizar ataques ataques de secuencias de comandos a través de la etiqueta descripción de un feed RSS.\r\n\r\n"
    }
  ],
  "lastModified": "2026-06-16T23:13:02.540",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sage.mozdev:sage:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A10F3C51-FECD-4010-B354-6311E981C8E5",
              "versionEndIncluding": "1.4.3"
            },
            {
              "criteria": "cpe:2.3:a:sage.mozdev:sage:1.3.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FB1A380-665E-4766-9BA2-730C3BDF4BD9"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14E6A30E-7577-4569-9309-53A0AF7FE3AC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "evaluatorImpact": "Per info from the following advisory: \r\n\r\nhttp://www.net-security.org/secworld.php?id=8527\r\n\r\nScored this CVE CIA:complete",
  "sourceIdentifier": "cve@mitre.org"
}