CVE-2009-3988
Vulnerability Summary
Timeline
Description
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.
CVSS Metrics
- v2.0•MEDIUM•Score: 5AV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 0.40%• Percentile: 61%
Techniques & Countermeasures
- CWE-264•Permissions, Privileges, and Access Controls
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Affected Systems
- mozilla•firefox
≤ 3.0.17 | 3.0 | 3.0.1 | 3.0.2 | 3.0.3 | 3.0.4 | 3.0.5 | 3.0.6 | 3.0.7 | 3.0.8 | 3.0.9 | 3.0.10 | 3.0.11 | 3.0.12 | 3.0.13 | 3.0.14 | 3.0.15 | 3.5 | 3.5.1 | 3.5.2 | 3.5.3 | 3.5.4 | 3.5.5 | 3.5.6 | 3.5.7
- mozilla•seamonkey
2.0 | 2.0:alpha_1 | 2.0:alpha_2 | 2.0:alpha_3 | 2.0:beta_1 | 2.0:beta_2 | 2.0:rc1 | 2.0:rc2
References (17)
- http://www.ubuntu.com/usn/USN-895-1
- http://secunia.com/advisories/38847
- http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:042
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.html
- http://www.redhat.com/support/errata/RHSA-2010-0112.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.html
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8355
- http://www.debian.org/security/2010/dsa-1999
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56362
- http://www.ubuntu.com/usn/USN-896-1
- http://www.vupen.com/english/advisories/2010/0405
- http://secunia.com/advisories/37242
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9384
- http://www.mozilla.org/security/announce/2010/mfsa2010-04.html
- https://bugzilla.mozilla.org/show_bug.cgi?id=504862