CVE-2009-0776
published 2009-03-05CVE-2009-0776: nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin…
PriorityP425high7.1CVSS 2.0
AVNACMAuNCCINAN
EPSS
1.60%
73.1th percentile
nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.6 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:C/I:N/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2009-03-19·CVSS 10.0
CVE-2009-0352 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Several flaws were discovered in the browser engine. If Javascript were
enabled, an attacker could exploit these flaws to crash Thunderbird and
possibly execute arbitrary code with user privileges. (CVE-2009-0352)
Jesse Ruderman and Gary Kwong discovered flaws in the browser engine. If a
user had Javascript enabled, these problems could allow a remote attacker to
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-0772, CVE-2009-0774)
Georgi Guninski discovered a flaw when Thunderbird performed a cross-domain
redirect. If a user had Javascript enabled, an attacker could bypass the
same-origin policy in Thunderbird by utilizing nsIRDFService an
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2009-03-06·CVSS 9.3
CVE-2009-0776 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Jesse Ruderman and Gary Kwong discovered flaws in the browser engine.
If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary
code with the privileges of the user invoking the program.
(CVE-2009-0772, CVE-2009-0774)
Georgi Guninski discovered a flaw when Firefox performed a
cross-domain redirect. An attacker could bypass the same-origin policy
in Firefox by utilizing nsIRDFService and steal private data from
users authenticated to the redirected website. (CVE-2009-0776)
Instructions: After a standard system upgrade you need to restart Firefox to effect the
necessary changes.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2009-03-06·CVSS 9.3
CVE-2009-0772 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Jesse Ruderman and Gary Kwong discovered flaws in the browser engine.
If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary
code with the privileges of the user invoking the program.
(CVE-2009-0772, CVE-2009-0774)
Georgi Guninski discovered a flaw when Firefox performed a
cross-domain redirect. An attacker could bypass the same-origin policy
in Firefox by utilizing nsIRDFService and steal private data from
users authenticated to the redirected website. (CVE-2009-0776)
Instructions: After a standard system upgrade you need to restart Firefox to effect the
necessary changes.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-03-05·CVSS 6.8
CVE-2009-0773 [MEDIUM] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Glenn Randers-Pehrson discovered that the embedded libpng in Firefox
did not properly initialize pointers. If a user were tricked into
viewing a malicious website with a crafted PNG file, a remote attacker
could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-0040)
Martijn Wargers, Jesse Ruderman, Josh Soref, Gary Kwong, and Timothee
Groleau discovered flaws in the browser engine. If a user were tricked
into viewing a malicious website, a remote attacker could cause a
denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-0771,
CVE-2009-0772, CVE-2009-0773, CV
Red Hat
Firefox XML data theft via RDFXMLDataSource and cross-domain redirect
vendor_redhat·2009-03-04·CVSS 7.1
CVE-2009-0776 [HIGH] Firefox XML data theft via RDFXMLDataSource and cross-domain redirect
Firefox XML data theft via RDFXMLDataSource and cross-domain redirect
nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.
GHSA
GHSA-rq9h-6m6h-p32x: nsIRDFService in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-0776 [HIGH] CWE-200 GHSA-rq9h-6m6h-p32x: nsIRDFService in Mozilla Firefox before 3
nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.htmlhttp://secunia.com/advisories/34137http://secunia.com/advisories/34140http://secunia.com/advisories/34145http://secunia.com/advisories/34272http://secunia.com/advisories/34324http://secunia.com/advisories/34383http://secunia.com/advisories/34387http://secunia.com/advisories/34417http://secunia.com/advisories/34462http://secunia.com/advisories/34464http://secunia.com/advisories/34527http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.405420http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.433952http://support.avaya.com/elmodocs2/security/ASA-2009-069.htmhttp://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.productID=154235&temp.releaseID=361845&temp.bucketID=126655&PAGE=Documenthttp://www.debian.org/security/2009/dsa-1751http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:075http://www.mandriva.com/security/advisories?name=MDVSA-2009:083http://www.mozilla.org/security/announce/2009/mfsa2009-09.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0258.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0315.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0325.htmlhttp://www.securityfocus.com/bid/33990http://www.securitytracker.com/id?1021797http://www.vupen.com/english/advisories/2009/0632https://bugzilla.mozilla.org/show_bug.cgi?id=414540https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5956https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6017https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6191https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7390https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9241https://usn.ubuntu.com/741-1/https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00009.htmlhttp://secunia.com/advisories/34137http://secunia.com/advisories/34140http://secunia.com/advisories/34145http://secunia.com/advisories/34272http://secunia.com/advisories/34324http://secunia.com/advisories/34383http://secunia.com/advisories/34387http://secunia.com/advisories/34417http://secunia.com/advisories/34462http://secunia.com/advisories/34464http://secunia.com/advisories/34527http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.405420http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.433952http://support.avaya.com/elmodocs2/security/ASA-2009-069.htmhttp://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.productID=154235&temp.releaseID=361845&temp.bucketID=126655&PAGE=Documenthttp://www.debian.org/security/2009/dsa-1751http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:075http://www.mandriva.com/security/advisories?name=MDVSA-2009:083http://www.mozilla.org/security/announce/2009/mfsa2009-09.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0258.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0315.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0325.htmlhttp://www.securityfocus.com/bid/33990http://www.securitytracker.com/id?1021797http://www.vupen.com/english/advisories/2009/0632https://bugzilla.mozilla.org/show_bug.cgi?id=414540https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5956https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6017https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6191https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7390https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9241https://usn.ubuntu.com/741-1/https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00769.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00771.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg01077.html
2009-03-05
Published