CVE-2009-1840
published 2009-06-12CVE-2009-1840: Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote…
PriorityP430critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.22%
80.9th percentile
Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.10 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qvp9-wp54-hp75: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-1840 [HIGH] GHSA-qvp9-wp54-hp75: Mozilla Firefox before 3
Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-06-12·CVSS 9.3
CVE-2009-1841 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Several flaws were discovered in the browser and JavaScript engines of
Firefox. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-1392,
CVE-2009-1832, CVE-2009-1833, CVE-2009-1837, CVE-2009-1838)
Pavel Cvrcek discovered that Firefox would sometimes display certain
invalid Unicode characters as whitespace. An attacker could exploit this to
spoof the location bar, such as in a phishing attack. (CVE-2009-1834)
Gregory Fleischer, Adam Barth and Collin Jackson discovered that Firefox
would allow access to local files from resources loaded via the
Red Hat
Firefox XUL scripts skip some security checks
vendor_redhat·2009-06-11·CVSS 9.3
CVE-2009-1840 [CRITICAL] Firefox XUL scripts skip some security checks
Firefox XUL scripts skip some security checks
Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.
No detection rules found.
http://osvdb.org/55158http://secunia.com/advisories/35331http://secunia.com/advisories/35415http://secunia.com/advisories/35431http://secunia.com/advisories/35439http://secunia.com/advisories/35440http://secunia.com/advisories/35468http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1http://www.debian.org/security/2009/dsa-1820http://www.mandriva.com/security/advisories?name=MDVSA-2009:141http://www.mozilla.org/security/announce/2009/mfsa2009-31.htmlhttp://www.securityfocus.com/bid/35326http://www.securitytracker.com/id?1022379http://www.vupen.com/english/advisories/2009/1572https://bugzilla.mozilla.org/show_bug.cgi?id=477979https://bugzilla.redhat.com/show_bug.cgi?id=503582https://exchange.xforce.ibmcloud.com/vulnerabilities/51076https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9448https://rhn.redhat.com/errata/RHSA-2009-1095.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.htmlhttp://osvdb.org/55158http://secunia.com/advisories/35331http://secunia.com/advisories/35415http://secunia.com/advisories/35431http://secunia.com/advisories/35439http://secunia.com/advisories/35440http://secunia.com/advisories/35468http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1http://www.debian.org/security/2009/dsa-1820http://www.mandriva.com/security/advisories?name=MDVSA-2009:141http://www.mozilla.org/security/announce/2009/mfsa2009-31.htmlhttp://www.securityfocus.com/bid/35326http://www.securitytracker.com/id?1022379http://www.vupen.com/english/advisories/2009/1572https://bugzilla.mozilla.org/show_bug.cgi?id=477979https://bugzilla.redhat.com/show_bug.cgi?id=503582https://exchange.xforce.ibmcloud.com/vulnerabilities/51076https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9448https://rhn.redhat.com/errata/RHSA-2009-1095.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.html
2009-06-12
Published