CVE-2009-1311
published 2009-04-22CVE-2009-1311: Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.31%
81.6th percentile
Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded frame, which causes POST data from an outer page to be sent to the inner frame's URL during a SAVEMODE_FILEONLY save of the inner frame.
Affected
112 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.8 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_ubuntu5.8MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-04-23·CVSS 5.8
CVE-2009-1302 [MEDIUM] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Several flaws were discovered in the browser engine. If a user were tricked
into viewing a malicious website, a remote attacker could cause a denial of
service or possibly execute arbitrary code with the privileges of the user
invoking the program. (CVE-2009-1302, CVE-2009-1303, CVE-2009-1304,
CVE-2009-1305)
It was discovered that Firefox displayed certain Unicode characters which
could be visually confused with punctuation in valid web addresses in the
location bar. An attacker could exploit this to spoof the location bar,
such as in a phishing attack. (CVE-2009-0652)
Several flaws were discovered in the way Firefox processed malformed URI
schemes. If a user were tricked into viewing a maliciou
Red Hat
Firefox POST data sent to wrong site when saving web page with embedded frame
vendor_redhat·2009-04-21·CVSS 4.3
CVE-2009-1311 [MEDIUM] Firefox POST data sent to wrong site when saving web page with embedded frame
Firefox POST data sent to wrong site when saving web page with embedded frame
Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded frame, which causes POST data from an outer page to be sent to the inner frame's URL during a SAVEMODE_FILEONLY save of the inner frame.
GHSA
GHSA-6jvr-wqq8-f5hr: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-1311 [MEDIUM] CWE-200 GHSA-6jvr-wqq8-f5hr: Mozilla Firefox before 3
Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded frame, which causes POST data from an outer page to be sent to the inner frame's URL during a SAVEMODE_FILEONLY save of the inner frame.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2009-0437.htmlhttp://secunia.com/advisories/34758http://secunia.com/advisories/34843http://secunia.com/advisories/34844http://secunia.com/advisories/34894http://secunia.com/advisories/35042http://secunia.com/advisories/35065http://secunia.com/advisories/35561http://secunia.com/advisories/35882http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1http://www.debian.org/security/2009/dsa-1797http://www.mandriva.com/security/advisories?name=MDVSA-2009:111http://www.mozilla.org/security/announce/2009/mfsa2009-21.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0436.htmlhttp://www.securityfocus.com/bid/34656http://www.securitytracker.com/id?1022097http://www.vupen.com/english/advisories/2009/1125https://bugzilla.mozilla.org/show_bug.cgi?id=471962https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10939https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6200https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6222https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7235https://usn.ubuntu.com/764-1/https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2009-0437.htmlhttp://secunia.com/advisories/34758http://secunia.com/advisories/34843http://secunia.com/advisories/34844http://secunia.com/advisories/34894http://secunia.com/advisories/35042http://secunia.com/advisories/35065http://secunia.com/advisories/35561http://secunia.com/advisories/35882http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1http://www.debian.org/security/2009/dsa-1797http://www.mandriva.com/security/advisories?name=MDVSA-2009:111http://www.mozilla.org/security/announce/2009/mfsa2009-21.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0436.htmlhttp://www.securityfocus.com/bid/34656http://www.securitytracker.com/id?1022097http://www.vupen.com/english/advisories/2009/1125https://bugzilla.mozilla.org/show_bug.cgi?id=471962https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10939https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6200https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6222https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7235https://usn.ubuntu.com/764-1/https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.html
2009-04-22
Published