CVE-2009-3014
published 2009-08-31CVE-2009-3014: Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly handle javascript: URIs in…
PriorityP413medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.99%
58.9th percentile
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location HTTP response header or (2) specifying the content of a Location HTTP response header.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.13 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | mozilla | <= 1.7 | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xw9p-2mr3-g9mx: Mozilla Firefox 3
ghsa_unreviewed·2022-05-02
CVE-2009-3014 [MEDIUM] CWE-79 GHSA-xw9p-2mr3-g9mx: Mozilla Firefox 3
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location HTTP response header or (2) specifying the content of a Location HTTP response header.
Red Hat
firefox/seamonkey: XSS via improper handling of javascript: URIs in certain HTML links
vendor_redhat·2009-07-30·CVSS 4.3
CVE-2009-3014 [MEDIUM] CWE-79 firefox/seamonkey: XSS via improper handling of javascript: URIs in certain HTML links
firefox/seamonkey: XSS via improper handling of javascript: URIs in certain HTML links
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location HTTP response header or (2) specifying the content of a Location HTTP response header.
No detection rules found.
No public exploits indexed.
http://websecurity.com.ua/3373/http://websecurity.com.ua/3386/http://www.securityfocus.com/archive/1/506163/100/0/threadedhttps://exchange.xforce.ibmcloud.com/vulnerabilities/52995http://websecurity.com.ua/3373/http://websecurity.com.ua/3386/http://www.securityfocus.com/archive/1/506163/100/0/threadedhttps://exchange.xforce.ibmcloud.com/vulnerabilities/52995
2009-08-31
Published