CVE-2009-3983
published 2009-12-17CVE-2009-3983: Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to send authenticated requests to arbitrary…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.20%
80.5th percentile
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to send authenticated requests to arbitrary applications by replaying the NTLM credentials of a browser user.
Affected
135 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.15 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_ubuntu9.3CRITICAL
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2010-03-18·CVSS 6.8
CVE-2009-0689 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Several flaws were discovered in the JavaScript engine of Thunderbird. If a
user had JavaScript enabled and were tricked into viewing malicious web
content, a remote attacker could cause a denial of service or possibly
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2009-0689, CVE-2009-2463, CVE-2009-3075)
Josh Soref discovered that the BinHex decoder used in Thunderbird contained
a flaw. If a user were tricked into viewing malicious content, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-3072)
It was discovered that Thunderbird did not properly manage memory when
using XUL tree el
Ubuntu
Firefox 3.5 and Xulrunner 1.9.1 regression
vendor_ubuntu·2010-01-08·CVSS 9.3
[CRITICAL] Firefox 3.5 and Xulrunner 1.9.1 regression
Title: Firefox 3.5 and Xulrunner 1.9.1 regression
Summary: Firefox 3.5 and Xulrunner 1.9.1 regression
USN-874-1 fixed vulnerabilities in Firefox and Xulrunner. The upstream
changes introduced a regression when using NTLM authentication. This update
fixes the problem and adds additional stability fixes.
We apologize for the inconvenience.
Original advisory details:
Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and
David James discovered several flaws in the browser and JavaScript engines
of Firefox. If a user were tricked into viewing a malicious website, a
remote attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2009-3979, CVE-2009-3980, CVE-2009-3982, CVE-2009-3986)
Takehiro T
Ubuntu
Firefox 3.0 and Xulrunner 1.9 regression
vendor_ubuntu·2010-01-08·CVSS 9.3
[CRITICAL] Firefox 3.0 and Xulrunner 1.9 regression
Title: Firefox 3.0 and Xulrunner 1.9 regression
Summary: Firefox 3.0 and Xulrunner 1.9 regression
USN-873-1 fixed vulnerabilities in Firefox and Xulrunner. The upstream
changes introduced a regression when using NTLM authentication. This update
fixes the problem and adds additional stability fixes.
We apologize for the inconvenience.
Original advisory details:
Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and
David James discovered several flaws in the browser and JavaScript engines
of Firefox. If a user were tricked into viewing a malicious website, a
remote attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2009-3979, CVE-2009-3981, CVE-2009-3986)
Takehiro Takahashi discovere
Ubuntu
Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
vendor_ubuntu·2009-12-18·CVSS 9.3
CVE-2009-3979 [CRITICAL] Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Title: Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Summary: Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and
David James discovered several flaws in the browser and JavaScript engines
of Firefox. If a user were tricked into viewing a malicious website, a
remote attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2009-3979, CVE-2009-3980, CVE-2009-3982, CVE-2009-3986)
Takehiro Takahashi discovered flaws in the NTLM implementation in Firefox.
If an NTLM authenticated user visited a malicious website, a remote
attacker could send requests to other applications, authenticated as the
user. (CVE-2009-3983)
Jonathan Morgan discovered t
Ubuntu
Firefox 3.0 and Xulrunner 1.9 vulnerabilities
vendor_ubuntu·2009-12-18·CVSS 9.3
CVE-2009-3979 [CRITICAL] Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Title: Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Summary: Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and
David James discovered several flaws in the browser and JavaScript engines
of Firefox. If a user were tricked into viewing a malicious website, a
remote attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2009-3979, CVE-2009-3981, CVE-2009-3986)
Takehiro Takahashi discovered flaws in the NTLM implementation in Firefox.
If an NTLM authenticated user visited a malicious website, a remote
attacker could send requests to other applications, authenticated as the
user. (CVE-2009-3983)
Jonathan Morgan discovered that Firefox did not
Red Hat
Mozilla NTLM reflection vulnerability
vendor_redhat·2009-12-15·CVSS 6.8
CVE-2009-3983 [MEDIUM] Mozilla NTLM reflection vulnerability
Mozilla NTLM reflection vulnerability
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to send authenticated requests to arbitrary applications by replaying the NTLM credentials of a browser user.
GHSA
GHSA-c965-xrgf-38h8: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-3983 [MEDIUM] GHSA-c965-xrgf-38h8: Mozilla Firefox before 3
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to send authenticated requests to arbitrary applications by replaying the NTLM credentials of a browser user.
No detection rules found.
http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/37699http://secunia.com/advisories/37703http://secunia.com/advisories/37704http://secunia.com/advisories/37785http://secunia.com/advisories/37813http://secunia.com/advisories/37856http://secunia.com/advisories/37881http://secunia.com/advisories/38977http://secunia.com/advisories/39001http://securitytracker.com/id?1023340http://securitytracker.com/id?1023341http://www.debian.org/security/2009/dsa-1956http://www.mozilla.org/security/announce/2009/mfsa2009-68.htmlhttp://www.novell.com/linux/security/advisories/2009_63_firefox.htmlhttp://www.securityfocus.com/bid/37349http://www.securityfocus.com/bid/37366http://www.ubuntu.com/usn/USN-873-1http://www.ubuntu.com/usn/USN-874-1http://www.ubuntu.com/usn/USN-915-1http://www.vupen.com/english/advisories/2009/3547http://www.vupen.com/english/advisories/2010/0648https://bugzilla.mozilla.org/show_bug.cgi?id=487872https://bugzilla.redhat.com/show_bug.cgi?id=546720https://exchange.xforce.ibmcloud.com/vulnerabilities/54807https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10047https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8240https://rhn.redhat.com/errata/RHSA-2009-1673.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1674.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00995.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg01034.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg01041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlhttp://secunia.com/advisories/37699http://secunia.com/advisories/37703http://secunia.com/advisories/37704http://secunia.com/advisories/37785http://secunia.com/advisories/37813http://secunia.com/advisories/37856http://secunia.com/advisories/37881http://secunia.com/advisories/38977http://secunia.com/advisories/39001http://securitytracker.com/id?1023340http://securitytracker.com/id?1023341http://www.debian.org/security/2009/dsa-1956http://www.mozilla.org/security/announce/2009/mfsa2009-68.htmlhttp://www.novell.com/linux/security/advisories/2009_63_firefox.htmlhttp://www.securityfocus.com/bid/37349http://www.securityfocus.com/bid/37366http://www.ubuntu.com/usn/USN-873-1http://www.ubuntu.com/usn/USN-874-1http://www.ubuntu.com/usn/USN-915-1http://www.vupen.com/english/advisories/2009/3547http://www.vupen.com/english/advisories/2010/0648https://bugzilla.mozilla.org/show_bug.cgi?id=487872https://bugzilla.redhat.com/show_bug.cgi?id=546720https://exchange.xforce.ibmcloud.com/vulnerabilities/54807https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10047https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8240https://rhn.redhat.com/errata/RHSA-2009-1673.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1674.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00995.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg01034.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg01041.html
2009-12-17
Published