CVE-2009-4102

Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.

Date published : 2009-11-28

http://www.securityfocus.com/bid/37120

http://www.debian.org/security/2009/dsa-1951