VYPR
Unrated severityNVD Advisory· Published Sep 9, 2010· Updated Apr 29, 2026

CVE-2010-2763

CVE-2010-2763

Description

The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2010-2763 is a same-origin policy bypass in Mozilla's XPCSafeJSObjectWrapper (SJOW) that allows XSS via crafted scripted functions, affecting Firefox, Thunderbird, and SeaMonkey.

Vulnerability

The vulnerability resides in the XPCSafeJSObjectWrapper (SJOW) implementation on the Mozilla 1.9.1 development branch. The class does not properly restrict scripted functions, allowing a crafted function to be executed in the context of another site. This affects Mozilla Firefox before version 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7. [1][3]

Exploitation

An attacker can create a scripted function whose parent is an outer window. When this function is called, arrays created within it originate from the current inner window, thereby bypassing the same-origin policy. The attacker needs only the ability to run JavaScript in a web page; no additional authentication or network position is required. The crafted function can then access data from a different origin, such as cookies. [1]

Impact

Successful exploitation enables cross-site scripting (XSS) attacks, allowing the attacker to read cookies, modify page content, or perform actions on behalf of the victim on a different site. This constitutes a violation of the same-origin policy and can lead to information disclosure and session hijacking. [3]

Mitigation

Mozilla released fixes in Firefox 3.5.12, Thunderbird 3.0.7, and SeaMonkey 2.0.7 on September 7, 2010. Users should update to these versions or later. No workarounds are documented. [3]

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

205
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 84 more
    • cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <=3.5.11
    • cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.0:preview_release:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5:beta1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:1.5:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.15:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.16:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.17:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.18:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.19:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.20:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:2.0.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.15:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.16:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.17:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:firefox:3.5.9:*:*:*:*:*:*:*
    • (no CPE)range: <3.5.12
  • cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*+ 52 more
    • cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*range: <=2.0.6
    • cpe:2.3:a:mozilla:seamonkey:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0:alpha:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.15:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.16:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.17:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.18:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.19:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1:alpha:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.1:beta:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.5.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.5.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:1.5.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0a1pre:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:beta_1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:beta_2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:seamonkey:2.0:rc2:*:*:*:*:*:*
    • (no CPE)range: <2.0.7
  • cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*+ 66 more
    • cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*range: <=3.0.6
    • cpe:2.3:a:mozilla:thunderbird:0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:0.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:0.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:0.7.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.0.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:1.5:beta2:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.14:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.16:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.17:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.18:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.19:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.21:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.22:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.23:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:2.0.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:thunderbird:3.0.5:*:*:*:*:*:*:*
    • (no CPE)range: <3.0.7

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.