CVE-2008-3837
published 2008-09-24CVE-2008-3837: Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click…
PriorityP335critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.27%
87.0th percentile
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| mozilla | firefox | < 2.0.0.17 | 2.0.0.17 |
| mozilla | firefox | >= 3.0 < 3.0.2 | 3.0.2 |
| mozilla | seamonkey | < 1.1.12 | 1.1.12 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_ubuntu10.0CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and xulrunner regression
vendor_ubuntu·2008-09-25·CVSS 10.0
[CRITICAL] Firefox and xulrunner regression
Title: Firefox and xulrunner regression
Summary: Firefox and xulrunner regression
USN-645-1 fixed vulnerabilities in Firefox and xulrunner. The upstream
patches introduced a regression in the saved password handling. While
password data was not lost, if a user had saved any passwords with
non-ASCII characters, Firefox could not access the password database.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Justin Schuh, Tom Cross and Peter Williams discovered errors in the
Firefox URL parsing routines. If a user were tricked into opening a
crafted hyperlink, an attacker could overflow a stack buffer and
execute arbitrary code. (CVE-2008-0016)
It was discovered that the same-origin check in Firefox could be
bypassed. If a user were tricked i
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-09-24·CVSS 10.0
CVE-2008-0016 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
USN-645-1 fixed vulnerabilities in Firefox and xulrunner for Ubuntu
7.04, 7.10 and 8.04 LTS. This provides the corresponding update for
Ubuntu 6.06 LTS.
Original advisory details:
Justin Schuh, Tom Cross and Peter Williams discovered errors in the
Firefox URL parsing routines. If a user were tricked into opening a
crafted hyperlink, an attacker could overflow a stack buffer and
execute arbitrary code. (CVE-2008-0016)
It was discovered that the same-origin check in Firefox could be
bypassed. If a user were tricked into opening a malicious website,
an attacker may be able to execute JavaScript in the context of a
different website. (CVE-2008-3835)
Several problems were discovered in the JavaScript engine. This
could allow
Ubuntu
Firefox and xulrunner vulnerabilities
vendor_ubuntu·2008-09-24·CVSS 10.0
CVE-2008-0016 [CRITICAL] Firefox and xulrunner vulnerabilities
Title: Firefox and xulrunner vulnerabilities
Summary: Firefox and xulrunner vulnerabilities
Justin Schuh, Tom Cross and Peter Williams discovered errors in the
Firefox URL parsing routines. If a user were tricked into opening a
crafted hyperlink, an attacker could overflow a stack buffer and
execute arbitrary code. (CVE-2008-0016)
It was discovered that the same-origin check in Firefox could be
bypassed. If a user were tricked into opening a malicious website,
an attacker may be able to execute JavaScript in the context of a
different website. (CVE-2008-3835)
Several problems were discovered in the JavaScript engine. This
could allow an attacker to execute scripts from page content with
chrome privileges. (CVE-2008-3836)
Paul Nickerson discovered Firefox did not properly process mouse
Red Hat
mozilla: Forced mouse drag
vendor_redhat·2008-09-23·CVSS 7.5
CVE-2008-3837 [HIGH] mozilla: Forced mouse drag
mozilla: Forced mouse drag
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.
GHSA
GHSA-w2pf-f3c3-85m7: Mozilla Firefox before 2
ghsa_unreviewed·2022-05-02·CVSS 7.5
CVE-2008-3837 [HIGH] GHSA-w2pf-f3c3-85m7: Mozilla Firefox before 2
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.
No detection rules found.
No public exploits indexed.
http://download.novell.com/Download?buildid=WZXONb-tqBw~http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.htmlhttp://secunia.com/advisories/31984http://secunia.com/advisories/31985http://secunia.com/advisories/31987http://secunia.com/advisories/32010http://secunia.com/advisories/32011http://secunia.com/advisories/32012http://secunia.com/advisories/32042http://secunia.com/advisories/32044http://secunia.com/advisories/32089http://secunia.com/advisories/32095http://secunia.com/advisories/32096http://secunia.com/advisories/32144http://secunia.com/advisories/32185http://secunia.com/advisories/32196http://secunia.com/advisories/32845http://secunia.com/advisories/33433http://secunia.com/advisories/34501http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.379422http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.405232http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.debian.org/security/2008/dsa-1649http://www.debian.org/security/2008/dsa-1669http://www.debian.org/security/2009/dsa-1697http://www.mandriva.com/security/advisories?name=MDVSA-2008:205http://www.mozilla.org/security/announce/2008/mfsa2008-40.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0879.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0882.htmlhttp://www.securityfocus.com/bid/31346http://www.securitytracker.com/id?1020922http://www.ubuntu.com/usn/usn-645-1http://www.ubuntu.com/usn/usn-645-2http://www.vupen.com/english/advisories/2008/2661http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=329385https://exchange.xforce.ibmcloud.com/vulnerabilities/45348https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9950https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01335.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg01384.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg01403.htmlhttp://download.novell.com/Download?buildid=WZXONb-tqBw~http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.htmlhttp://secunia.com/advisories/31984http://secunia.com/advisories/31985http://secunia.com/advisories/31987http://secunia.com/advisories/32010http://secunia.com/advisories/32011http://secunia.com/advisories/32012http://secunia.com/advisories/32042http://secunia.com/advisories/32044http://secunia.com/advisories/32089http://secunia.com/advisories/32095http://secunia.com/advisories/32096http://secunia.com/advisories/32144http://secunia.com/advisories/32185http://secunia.com/advisories/32196http://secunia.com/advisories/32845http://secunia.com/advisories/33433http://secunia.com/advisories/34501http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.379422http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.405232http://sunsolve.sun.com/search/document.do?assetkey=1-26-256408-1http://www.debian.org/security/2008/dsa-1649http://www.debian.org/security/2008/dsa-1669http://www.debian.org/security/2009/dsa-1697http://www.mandriva.com/security/advisories?name=MDVSA-2008:205http://www.mozilla.org/security/announce/2008/mfsa2008-40.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0879.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0882.htmlhttp://www.securityfocus.com/bid/31346http://www.securitytracker.com/id?1020922http://www.ubuntu.com/usn/usn-645-1http://www.ubuntu.com/usn/usn-645-2http://www.vupen.com/english/advisories/2008/2661http://www.vupen.com/english/advisories/2009/0977https://bugzilla.mozilla.org/show_bug.cgi?id=329385https://exchange.xforce.ibmcloud.com/vulnerabilities/45348https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9950https://www.redhat.com/archives/fedora-package-announce/2008-September/msg01335.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg01384.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-September/msg01403.html
2008-09-24
Published