CVE-2009-1838
published 2009-06-12CVE-2009-1838: The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner…
critical9.3CVSS 3.1
AVNACMAuNCCICAC
The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted event handler, related to an incorrect context for this event handler.
Affected
180 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.10 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2009-06-25·CVSS 5.0
CVE-2009-1303 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Several flaws were discovered in the JavaScript engine of Thunderbird. If a
user had JavaScript enabled and were tricked into viewing malicious web
content, a remote attacker could cause a denial of service or possibly
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2009-1303, CVE-2009-1305, CVE-2009-1392, CVE-2009-1833,
CVE-2009-1838)
Several flaws were discovered in the way Thunderbird processed malformed
URI schemes. If a user were tricked into viewing a malicious website and
had JavaScript and plugins enabled, a remote attacker could execute
arbitrary JavaScript or steal private data. (CVE-2009-1306, CVE-2009-1307,
CVE-2009-1309)
Cefn Hoile discovered Thunderbird did not adequa
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-06-12·CVSS 9.3
CVE-2009-1841 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Several flaws were discovered in the browser and JavaScript engines of
Firefox. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-1392,
CVE-2009-1832, CVE-2009-1833, CVE-2009-1837, CVE-2009-1838)
Pavel Cvrcek discovered that Firefox would sometimes display certain
invalid Unicode characters as whitespace. An attacker could exploit this to
spoof the location bar, such as in a phishing attack. (CVE-2009-1834)
Gregory Fleischer, Adam Barth and Collin Jackson discovered that Firefox
would allow access to local files from resources loaded via the
Red Hat
Firefox arbitrary code execution flaw
vendor_redhat·2009-06-11·CVSS 9.3
CVE-2009-1838 [CRITICAL] Firefox arbitrary code execution flaw
Firefox arbitrary code execution flaw
The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted event handler, related to an incorrect context for this event handler.
GHSA
GHSA-p6f8-2h8r-5246: The garbage-collection implementation in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-1838 [HIGH] CWE-94 GHSA-p6f8-2h8r-5246: The garbage-collection implementation in Mozilla Firefox before 3
The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted event handler, related to an incorrect context for this event handler.
Kernel
namei: allow restricted O_CREAT of FIFOs and regular files
kernel_security·2018-08-23·CVSS 7.2
CVE-2000-1134 [HIGH] namei: allow restricted O_CREAT of FIFOs and regular files
namei: allow restricted O_CREAT of FIFOs and regular files
Disallows open of FIFOs or regular files not owned by the user in world
writable sticky directories, unless the owner is the same as that of the
directory or the file is opened without the O_CREAT flag. The purpose
is to make data spoofing attacks harder. This protection can be turned
on and off separately for FIFOs and regular files via sysctl, just like
the symlinks/hardlinks protection. This patch is based on Openwall's
"HARDEN_FIFO" feature by Solar Designer.
This is a brief list of old vulnerabilities that could have been prevented
by this feature, some of them even allow for privilege escalation:
CVE-2000-1134
CVE-2007-3852
CVE-2008-0525
CVE-2009-0416
CVE-2011-4834
CVE-2015-1838
CVE-2015-7442
CVE-2016-7489
This list is no
No detection rules found.
No public exploits indexed.
http://osvdb.org/55157http://rhn.redhat.com/errata/RHSA-2009-1096.htmlhttp://secunia.com/advisories/35331http://secunia.com/advisories/35415http://secunia.com/advisories/35428http://secunia.com/advisories/35431http://secunia.com/advisories/35439http://secunia.com/advisories/35440http://secunia.com/advisories/35468http://secunia.com/advisories/35536http://secunia.com/advisories/35561http://secunia.com/advisories/35602http://secunia.com/advisories/35882http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1http://www.debian.org/security/2009/dsa-1820http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:141http://www.mozilla.org/security/announce/2009/mfsa2009-29.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1125.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1126.htmlhttp://www.securityfocus.com/bid/35326http://www.securityfocus.com/bid/35383http://www.securitytracker.com/id?1022397http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.454275http://www.ubuntu.com/usn/usn-782-1http://www.vupen.com/english/advisories/2009/1572https://bugzilla.mozilla.org/show_bug.cgi?id=489131https://bugzilla.redhat.com/show_bug.cgi?id=503580https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11080https://rhn.redhat.com/errata/RHSA-2009-1095.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.htmlhttp://osvdb.org/55157http://rhn.redhat.com/errata/RHSA-2009-1096.htmlhttp://secunia.com/advisories/35331http://secunia.com/advisories/35415http://secunia.com/advisories/35428http://secunia.com/advisories/35431http://secunia.com/advisories/35439http://secunia.com/advisories/35440http://secunia.com/advisories/35468http://secunia.com/advisories/35536http://secunia.com/advisories/35561http://secunia.com/advisories/35602http://secunia.com/advisories/35882http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1http://www.debian.org/security/2009/dsa-1820http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:141http://www.mozilla.org/security/announce/2009/mfsa2009-29.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1125.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1126.htmlhttp://www.securityfocus.com/bid/35326http://www.securityfocus.com/bid/35383http://www.securitytracker.com/id?1022397http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.454275http://www.ubuntu.com/usn/usn-782-1http://www.vupen.com/english/advisories/2009/1572https://bugzilla.mozilla.org/show_bug.cgi?id=489131https://bugzilla.redhat.com/show_bug.cgi?id=503580https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11080https://rhn.redhat.com/errata/RHSA-2009-1095.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.html
2009-06-12
Published