CVE-2009-4100

UnknownEPSS 3.87%

Last modified

CVE-2009-4100 is a vulnerability of currently unknown severity. Yoono extension before 6.1.1 for Firefox performs certain operations with chrome privileges, which allows user-assisted remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via DOM event handlers such as onload.. EPSS estimates a 3.87% chance of exploitation in the next 30 days.

Description

Yoono extension before 6.1.1 for Firefox performs certain operations with chrome privileges, which allows user-assisted remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via DOM event handlers such as onload.

Metrics

EPSS Probability
3.87%

88.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
YoonoYoono<= 6.1.0
YoonoYoono2.0.2.474
YoonoYoono2.0.3.564
YoonoYoono2.0.4.641
YoonoYoono2.1.0.743
YoonoYoono2.2.1.1038
YoonoYoono3.0.0.1268
YoonoYoono3.0.0.1270
YoonoYoono3.0.1.1388
YoonoYoono3.0.2.1976
YoonoYoono3.0.3.2369
YoonoYoono3.0.4.2469
YoonoYoono3.0.5.2626
YoonoYoono3.0.6.2723
YoonoYoono3.1.0.2898
YoonoYoono3.1.1.2999
YoonoYoono4.0.0.4529
YoonoYoono4.0.1.4774
YoonoYoono4.0.2.5149
YoonoYoono4.0.3.5488
YoonoYoono5.0.1.11511_11520
YoonoYoono5.0.3
YoonoYoono5.0.4
YoonoYoono5.0.5
YoonoYoono5.0.6
YoonoYoono5.0.7
YoonoYoono5.0.7.2
YoonoYoono5.1.0
YoonoYoono5.2.0
YoonoYoono5.3.0
YoonoYoono5.4.0
YoonoYoono6.0.0
YoonoYoono6.0.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-4100?
Yoono extension before 6.1.1 for Firefox performs certain operations with chrome privileges, which allows user-assisted remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via DOM event handlers such as onload.
How severe is CVE-2009-4100?
Severity scoring for CVE-2009-4100 is pending analysis. The EPSS model estimates a 3.87% probability of exploitation in the next 30 days.
How do I fix CVE-2009-4100?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-4100?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST