CVE-2009-1835
published 2009-06-12CVE-2009-1835: Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.33%
81.7th percentile
Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via a crafted HTML document, as demonstrated by a URL with file://example.com/C:/ at the beginning.
Affected
112 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.10 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_ubuntu9.3CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-06-12·CVSS 9.3
CVE-2009-1841 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Several flaws were discovered in the browser and JavaScript engines of
Firefox. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-1392,
CVE-2009-1832, CVE-2009-1833, CVE-2009-1837, CVE-2009-1838)
Pavel Cvrcek discovered that Firefox would sometimes display certain
invalid Unicode characters as whitespace. An attacker could exploit this to
spoof the location bar, such as in a phishing attack. (CVE-2009-1834)
Gregory Fleischer, Adam Barth and Collin Jackson discovered that Firefox
would allow access to local files from resources loaded via the
Red Hat
file: resources
vendor_redhat·2009-06-11·CVSS 4.3
CVE-2009-1835 [MEDIUM] file: resources
file: resources
Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via a crafted HTML document, as demonstrated by a URL with file://example.com/C:/ at the beginning.
GHSA
GHSA-3679-rrg7-2vqr: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-1835 [MEDIUM] CWE-200 GHSA-3679-rrg7-2vqr: Mozilla Firefox before 3
Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via a crafted HTML document, as demonstrated by a URL with file://example.com/C:/ at the beginning.
No detection rules found.
http://osvdb.org/55161http://rhn.redhat.com/errata/RHSA-2009-1096.htmlhttp://secunia.com/advisories/35331http://secunia.com/advisories/35415http://secunia.com/advisories/35428http://secunia.com/advisories/35431http://secunia.com/advisories/35439http://secunia.com/advisories/35468http://secunia.com/advisories/35561http://secunia.com/advisories/35882http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408http://sunsolve.sun.com/search/document.do?assetkey=1-26-265068-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020800.1-1http://www.debian.org/security/2009/dsa-1820http://www.mozilla.org/security/announce/2009/mfsa2009-26.htmlhttp://www.securityfocus.com/bid/35326http://www.securityfocus.com/bid/35391http://www.vupen.com/english/advisories/2009/1572http://www.vupen.com/english/advisories/2009/2152https://bugzilla.mozilla.org/show_bug.cgi?id=491801https://bugzilla.redhat.com/show_bug.cgi?id=503576https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9803https://rhn.redhat.com/errata/RHSA-2009-1095.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.htmlhttp://osvdb.org/55161http://rhn.redhat.com/errata/RHSA-2009-1096.htmlhttp://secunia.com/advisories/35331http://secunia.com/advisories/35415http://secunia.com/advisories/35428http://secunia.com/advisories/35431http://secunia.com/advisories/35439http://secunia.com/advisories/35468http://secunia.com/advisories/35561http://secunia.com/advisories/35882http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408http://sunsolve.sun.com/search/document.do?assetkey=1-26-265068-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020800.1-1http://www.debian.org/security/2009/dsa-1820http://www.mozilla.org/security/announce/2009/mfsa2009-26.htmlhttp://www.securityfocus.com/bid/35326http://www.securityfocus.com/bid/35391http://www.vupen.com/english/advisories/2009/1572http://www.vupen.com/english/advisories/2009/2152https://bugzilla.mozilla.org/show_bug.cgi?id=491801https://bugzilla.redhat.com/show_bug.cgi?id=503576https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9803https://rhn.redhat.com/errata/RHSA-2009-1095.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.html
2009-06-12
Published