Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.html - | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.html - | |
References | () http://secunia.com/advisories/37242 - | |
References | () http://secunia.com/advisories/38847 - | |
References | () http://www.debian.org/security/2010/dsa-1999 - | |
References | () http://www.mandriva.com/security/advisories?name=MDVSA-2010:042 - | |
References | () http://www.mozilla.org/security/announce/2010/mfsa2010-04.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2010-0112.html - | |
References | () http://www.ubuntu.com/usn/USN-895-1 - | |
References | () http://www.ubuntu.com/usn/USN-896-1 - | |
References | () http://www.vupen.com/english/advisories/2010/0405 - | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=504862 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/56362 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8355 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9384 - |
Information
Published : 2010-02-22 13:00
Updated : 2024-11-21 01:08
NVD link : CVE-2009-3988
Mitre link : CVE-2009-3988
CVE.ORG link : CVE-2009-3988
JSON object : View
Products Affected
mozilla
- firefox
- seamonkey
CWE
CWE-264
Permissions, Privileges, and Access Controls