Security Advisory
CVE-2011-3655
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Mozilla Firefox 4.x through 7.0 and Thunderbird 5.0 through 7.0 perform access control without checking for use of the NoWaiverWrapper wrapper, which allows remote attackers to gain privileges via a crafted web site.