Vulnerabilities (CVE)

Filtered by vendor Christophe Thibault Subscribe
Filtered by product K-meleon
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-3008 1 Christophe Thibault 1 K-meleon 2024-02-04 4.3 MEDIUM N/A
K-Meleon 1.5.3 allows context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.