Heap
06-03-09, 03:40
nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0776)
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0776)