CVE-2009-3375Mozilla Firefox vulnerability

CWE-2646 documents5 sources
Severity
4.3MEDIUMNVD
EPSS
0.5%
top 35.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 29
Latest updateMay 2

Description

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/firefox18 versions+17

🔴Vulnerability Details

1
GHSA
GHSA-w757-mvqp-v98h: content/html/document/src/nsHTMLDocument2022-05-02

📋Vendor Advisories

3
Ubuntu
Firefox and Xulrunner regression2009-11-11
Ubuntu
Firefox and Xulrunner vulnerabilities2009-10-31
Red Hat
Firefox cross-origin data theft through document.getSelection()2009-10-27

💬Community

1
Bugzilla
CVE-2009-3375 Firefox cross-origin data theft through document.getSelection()2009-10-21