CVE-2009-1307
published 2009-04-22CVE-2009-1307: The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which…
PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.18%
80.6th percentile
The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI.
Affected
80 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.8 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2009-06-25·CVSS 5.0
CVE-2009-1303 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Several flaws were discovered in the JavaScript engine of Thunderbird. If a
user had JavaScript enabled and were tricked into viewing malicious web
content, a remote attacker could cause a denial of service or possibly
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2009-1303, CVE-2009-1305, CVE-2009-1392, CVE-2009-1833,
CVE-2009-1838)
Several flaws were discovered in the way Thunderbird processed malformed
URI schemes. If a user were tricked into viewing a malicious website and
had JavaScript and plugins enabled, a remote attacker could execute
arbitrary JavaScript or steal private data. (CVE-2009-1306, CVE-2009-1307,
CVE-2009-1309)
Cefn Hoile discovered Thunderbird did not adequa
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-04-23·CVSS 5.8
CVE-2009-1302 [MEDIUM] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Several flaws were discovered in the browser engine. If a user were tricked
into viewing a malicious website, a remote attacker could cause a denial of
service or possibly execute arbitrary code with the privileges of the user
invoking the program. (CVE-2009-1302, CVE-2009-1303, CVE-2009-1304,
CVE-2009-1305)
It was discovered that Firefox displayed certain Unicode characters which
could be visually confused with punctuation in valid web addresses in the
location bar. An attacker could exploit this to spoof the location bar,
such as in a phishing attack. (CVE-2009-0652)
Several flaws were discovered in the way Firefox processed malformed URI
schemes. If a user were tricked into viewing a maliciou
Red Hat
view-source: protocol
vendor_redhat·2009-04-21·CVSS 6.8
CVE-2009-1307 [MEDIUM] view-source: protocol
view-source: protocol
The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI.
GHSA
GHSA-5cxh-4rwm-2jh3: The view-source: URI implementation in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-1307 [MEDIUM] CWE-20 GHSA-5cxh-4rwm-2jh3: The view-source: URI implementation in Mozilla Firefox before 3
The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2009-0437.htmlhttp://secunia.com/advisories/34758http://secunia.com/advisories/34780http://secunia.com/advisories/34843http://secunia.com/advisories/34844http://secunia.com/advisories/34894http://secunia.com/advisories/35042http://secunia.com/advisories/35065http://secunia.com/advisories/35536http://secunia.com/advisories/35561http://secunia.com/advisories/35602http://secunia.com/advisories/35882http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1http://www.debian.org/security/2009/dsa-1797http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:111http://www.mandriva.com/security/advisories?name=MDVSA-2009:141http://www.mozilla.org/security/announce/2009/mfsa2009-17.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0436.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1125.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1126.htmlhttp://www.securityfocus.com/bid/34656http://www.securitytracker.com/id?1022093http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.454275http://www.ubuntu.com/usn/usn-782-1http://www.vupen.com/english/advisories/2009/1125https://bugzilla.mozilla.org/show_bug.cgi?id=481342https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10972https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5933https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6154https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6266https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7008https://usn.ubuntu.com/764-1/https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2009-0437.htmlhttp://secunia.com/advisories/34758http://secunia.com/advisories/34780http://secunia.com/advisories/34843http://secunia.com/advisories/34844http://secunia.com/advisories/34894http://secunia.com/advisories/35042http://secunia.com/advisories/35065http://secunia.com/advisories/35536http://secunia.com/advisories/35561http://secunia.com/advisories/35602http://secunia.com/advisories/35882http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1http://www.debian.org/security/2009/dsa-1797http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:111http://www.mandriva.com/security/advisories?name=MDVSA-2009:141http://www.mozilla.org/security/announce/2009/mfsa2009-17.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0436.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1125.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1126.htmlhttp://www.securityfocus.com/bid/34656http://www.securitytracker.com/id?1022093http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.454275http://www.ubuntu.com/usn/usn-782-1http://www.vupen.com/english/advisories/2009/1125https://bugzilla.mozilla.org/show_bug.cgi?id=481342https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10972https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5933https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6154https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6266https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7008https://usn.ubuntu.com/764-1/https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.html
2009-04-22
Published