CVE-2009-0354
published 2009-02-04CVE-2009-0354: Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the…
PriorityP48low2.6CVSS 2.0
AVNACHAuNCNIPAN
EPSS
2.32%
81.8th percentile
Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f7gf-49mv-q3m5: Cross-domain vulnerability in js/src/jsobj
ghsa_unreviewed·2022-05-02
CVE-2009-0354 [LOW] CWE-79 GHSA-f7gf-49mv-q3m5: Cross-domain vulnerability in js/src/jsobj
Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-02-10·CVSS 10.0
CVE-2009-0352 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Several flaws were discovered in the browser engine. These problems could allow
an attacker to crash the browser and possibly execute arbitrary code with user
privileges. (CVE-2009-0352, CVE-2009-0353)
A flaw was discovered in the JavaScript engine. An attacker could bypass the
same-origin policy in Firefox by utilizing a chrome XBL method and execute
arbitrary JavaScript within the context of another website. (CVE-2009-0354)
A flaw was discovered in the browser engine when restoring closed tabs. If a
user were tricked into restoring a tab to a malicious website with form input
controls, an attacker could steal local files on the user's system.
(CVE-2009-0355)
Wladimir Palant discovered that Fi
Red Hat
Firefox XSS using a chrome XBL method and window.eval
vendor_redhat·2009-02-03·CVSS 2.6
CVE-2009-0354 [LOW] CWE-79 Firefox XSS using a chrome XBL method and window.eval
Firefox XSS using a chrome XBL method and window.eval
Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2009-0256.htmlhttp://secunia.com/advisories/33799http://secunia.com/advisories/33809http://secunia.com/advisories/33831http://secunia.com/advisories/33841http://secunia.com/advisories/33846http://secunia.com/advisories/33869http://support.avaya.com/elmodocs2/security/ASA-2009-040.htmhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:044http://www.mozilla.org/security/announce/2009/mfsa2009-02.htmlhttp://www.securityfocus.com/bid/33598http://www.securitytracker.com/id?1021664http://www.ubuntu.com/usn/usn-717-1http://www.vupen.com/english/advisories/2009/0313https://bugzilla.mozilla.org/show_bug.cgi?id=468581https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9796https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-02/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2009-0256.htmlhttp://secunia.com/advisories/33799http://secunia.com/advisories/33809http://secunia.com/advisories/33831http://secunia.com/advisories/33841http://secunia.com/advisories/33846http://secunia.com/advisories/33869http://support.avaya.com/elmodocs2/security/ASA-2009-040.htmhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:044http://www.mozilla.org/security/announce/2009/mfsa2009-02.htmlhttp://www.securityfocus.com/bid/33598http://www.securitytracker.com/id?1021664http://www.ubuntu.com/usn/usn-717-1http://www.vupen.com/english/advisories/2009/0313https://bugzilla.mozilla.org/show_bug.cgi?id=468581https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9796https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00240.html
2009-02-04
Published