CVE-2009-3007
published 2009-08-28CVE-2009-3007: Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.64%
47.1th percentile
Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| flock | flock | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
seamonkey: local fake url/file same origin spoof
vendor_redhat·2009-08-15·CVSS 4.3
CVE-2009-3007 [MEDIUM] seamonkey: local fake url/file same origin spoof
seamonkey: local fake url/file same origin spoof
Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.
GHSA
GHSA-p7fh-hvqc-m963: Mozilla Firefox 3
ghsa_unreviewed·2022-05-02
CVE-2009-3007 [MEDIUM] GHSA-p7fh-hvqc-m963: Mozilla Firefox 3
Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.
No detection rules found.
No public exploits indexed.
2009-08-28
Published