⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2009-1308Cross-site Scripting in Mozilla Firefox

Severity
4.3MEDIUMNVD
EPSS
1.1%
top 21.94%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedApr 22
Latest updateMay 2

Description

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary web script or HTML via vectors involving XBL JavaScript bindings and remote stylesheets, as exploited in the wild by a March 2009 eBay listing.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/firefox3.0.8+87

🔴Vulnerability Details

2
GHSA
GHSA-chqp-7f63-6c5w: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 32022-05-02
VulnCheck
Mozilla Firefox Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2009

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2009-06-25
Ubuntu
Firefox and Xulrunner vulnerabilities2009-04-23
Red Hat
Firefox XSS hazard using third-party stylesheets and XBL bindings2009-04-21

💬Community

1
Bugzilla
CVE-2009-1308 Firefox XSS hazard using third-party stylesheets and XBL bindings2009-04-17