CVE-2009-3988

Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.
References
Link Resource
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.html
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.html
http://secunia.com/advisories/37242
http://secunia.com/advisories/38847
http://www.debian.org/security/2010/dsa-1999
http://www.mandriva.com/security/advisories?name=MDVSA-2010:042
http://www.mozilla.org/security/announce/2010/mfsa2010-04.html
http://www.redhat.com/support/errata/RHSA-2010-0112.html
http://www.ubuntu.com/usn/USN-895-1
http://www.ubuntu.com/usn/USN-896-1
http://www.vupen.com/english/advisories/2010/0405
https://bugzilla.mozilla.org/show_bug.cgi?id=504862
https://exchange.xforce.ibmcloud.com/vulnerabilities/56362
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8355
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9384
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.html
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.html
http://secunia.com/advisories/37242
http://secunia.com/advisories/38847
http://www.debian.org/security/2010/dsa-1999
http://www.mandriva.com/security/advisories?name=MDVSA-2010:042
http://www.mozilla.org/security/announce/2010/mfsa2010-04.html
http://www.redhat.com/support/errata/RHSA-2010-0112.html
http://www.ubuntu.com/usn/USN-895-1
http://www.ubuntu.com/usn/USN-896-1
http://www.vupen.com/english/advisories/2010/0405
https://bugzilla.mozilla.org/show_bug.cgi?id=504862
https://exchange.xforce.ibmcloud.com/vulnerabilities/56362
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8355
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9384
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.10:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.11:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.12:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.13:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.14:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.0.15:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:3.5.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:beta_1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:beta_2:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:seamonkey:2.0:rc2:*:*:*:*:*:*

History

21 Nov 2024, 01:08

Type Values Removed Values Added
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.html -
References () http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.html - () http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.html -
References () http://secunia.com/advisories/37242 - () http://secunia.com/advisories/37242 -
References () http://secunia.com/advisories/38847 - () http://secunia.com/advisories/38847 -
References () http://www.debian.org/security/2010/dsa-1999 - () http://www.debian.org/security/2010/dsa-1999 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2010:042 - () http://www.mandriva.com/security/advisories?name=MDVSA-2010:042 -
References () http://www.mozilla.org/security/announce/2010/mfsa2010-04.html - () http://www.mozilla.org/security/announce/2010/mfsa2010-04.html -
References () http://www.redhat.com/support/errata/RHSA-2010-0112.html - () http://www.redhat.com/support/errata/RHSA-2010-0112.html -
References () http://www.ubuntu.com/usn/USN-895-1 - () http://www.ubuntu.com/usn/USN-895-1 -
References () http://www.ubuntu.com/usn/USN-896-1 - () http://www.ubuntu.com/usn/USN-896-1 -
References () http://www.vupen.com/english/advisories/2010/0405 - () http://www.vupen.com/english/advisories/2010/0405 -
References () https://bugzilla.mozilla.org/show_bug.cgi?id=504862 - () https://bugzilla.mozilla.org/show_bug.cgi?id=504862 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/56362 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/56362 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8355 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8355 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9384 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9384 -

Information

Published : 2010-02-22 13:00

Updated : 2024-11-21 01:08


NVD link : CVE-2009-3988

Mitre link : CVE-2009-3988

CVE.ORG link : CVE-2009-3988


JSON object : View

Products Affected

mozilla

  • firefox
  • seamonkey
CWE
CWE-264

Permissions, Privileges, and Access Controls