CVE-2009-3986
published 2009-12-17CVE-2009-3986: Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome…
PriorityP337high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
3.71%
88.5th percentile
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property.
Affected
135 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.15 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_ubuntu9.3CRITICAL
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox 3.5 and Xulrunner 1.9.1 regression
vendor_ubuntu·2010-01-08·CVSS 9.3
[CRITICAL] Firefox 3.5 and Xulrunner 1.9.1 regression
Title: Firefox 3.5 and Xulrunner 1.9.1 regression
Summary: Firefox 3.5 and Xulrunner 1.9.1 regression
USN-874-1 fixed vulnerabilities in Firefox and Xulrunner. The upstream
changes introduced a regression when using NTLM authentication. This update
fixes the problem and adds additional stability fixes.
We apologize for the inconvenience.
Original advisory details:
Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and
David James discovered several flaws in the browser and JavaScript engines
of Firefox. If a user were tricked into viewing a malicious website, a
remote attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2009-3979, CVE-2009-3980, CVE-2009-3982, CVE-2009-3986)
Takehiro T
Ubuntu
Firefox 3.0 and Xulrunner 1.9 regression
vendor_ubuntu·2010-01-08·CVSS 9.3
[CRITICAL] Firefox 3.0 and Xulrunner 1.9 regression
Title: Firefox 3.0 and Xulrunner 1.9 regression
Summary: Firefox 3.0 and Xulrunner 1.9 regression
USN-873-1 fixed vulnerabilities in Firefox and Xulrunner. The upstream
changes introduced a regression when using NTLM authentication. This update
fixes the problem and adds additional stability fixes.
We apologize for the inconvenience.
Original advisory details:
Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and
David James discovered several flaws in the browser and JavaScript engines
of Firefox. If a user were tricked into viewing a malicious website, a
remote attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2009-3979, CVE-2009-3981, CVE-2009-3986)
Takehiro Takahashi discovere
Ubuntu
Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
vendor_ubuntu·2009-12-18·CVSS 9.3
CVE-2009-3979 [CRITICAL] Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Title: Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Summary: Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and
David James discovered several flaws in the browser and JavaScript engines
of Firefox. If a user were tricked into viewing a malicious website, a
remote attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2009-3979, CVE-2009-3980, CVE-2009-3982, CVE-2009-3986)
Takehiro Takahashi discovered flaws in the NTLM implementation in Firefox.
If an NTLM authenticated user visited a malicious website, a remote
attacker could send requests to other applications, authenticated as the
user. (CVE-2009-3983)
Jonathan Morgan discovered t
Ubuntu
Firefox 3.0 and Xulrunner 1.9 vulnerabilities
vendor_ubuntu·2009-12-18·CVSS 9.3
CVE-2009-3979 [CRITICAL] Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Title: Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Summary: Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel, Olli Pettay, and
David James discovered several flaws in the browser and JavaScript engines
of Firefox. If a user were tricked into viewing a malicious website, a
remote attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2009-3979, CVE-2009-3981, CVE-2009-3986)
Takehiro Takahashi discovered flaws in the NTLM implementation in Firefox.
If an NTLM authenticated user visited a malicious website, a remote
attacker could send requests to other applications, authenticated as the
user. (CVE-2009-3983)
Jonathan Morgan discovered that Firefox did not
Red Hat
Mozilla Chrome privilege escalation via window.opener
vendor_redhat·2009-12-15·CVSS 7.6
CVE-2009-3986 [HIGH] Mozilla Chrome privilege escalation via window.opener
Mozilla Chrome privilege escalation via window.opener
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property.
GHSA
GHSA-hm3p-p79c-ph3c: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-3986 [HIGH] CWE-94 GHSA-hm3p-p79c-ph3c: Mozilla Firefox before 3
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3986 Mozilla Chrome privilege escalation via window.opener
bugzilla·2009-12-11·CVSS 7.6
CVE-2009-3986 [HIGH] CVE-2009-3986 Mozilla Chrome privilege escalation via window.opener
CVE-2009-3986 Mozilla Chrome privilege escalation via window.opener
Security researcher David James reported that a content window which is opened by a chrome window retains a reference to the chrome window via the window.opener property. Via this reference, the newly opened content window can access functions inside the chrome window, such as eval, and use these functions to perform a privilege escalation and run arbitrary JavaScript code with chrome privileges. Because an attacker would need to find a browser dialog which opens a chrome privileged window then navigate the new window to an attacker-controlled page in order to leverage this vulnerability, the severity of this issue was determined to be moderate.
Discussion:
This issue has been addressed in following products:
Red Hat E
Bugzilla
CVE-2009-3241 Wireshark: DoS (excessive CPU use) in OPCUA dissector
bugzilla·2009-09-17·CVSS 7.8
CVE-2009-3241 [HIGH] CVE-2009-3241 Wireshark: DoS (excessive CPU use) in OPCUA dissector
CVE-2009-3241 Wireshark: DoS (excessive CPU use) in OPCUA dissector
A denial of service flaw was found in Wireshark's OPC Unified Architecture
(OPCUA) dissector. Decoding a specially-crafted OPCUA PCAP capture file in
Wireshark would lead to excessive CPU use.
References:
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3986
http://www.wireshark.org/security/wnpa-sec-2009-05.html
Reproducer:
1. Load the pcap file
2. Open "Decode as ..." dialog, select Transport destination(12001)
as "opcua", and press OK
3. Wireshark gets freezed (see top output) at the dialog for about
2 minutes, and then show the packets as OpcUa.
Upstream patch:
http://anonsvn.wireshark.org/viewvc?view=rev&revision=29813
Credit:
vieuxtech
Discussion:
This issue does NOT affect the versions of wireshark packag
http://secunia.com/advisories/37699http://secunia.com/advisories/37704http://secunia.com/advisories/37785http://secunia.com/advisories/37813http://secunia.com/advisories/37856http://secunia.com/advisories/37881http://securitytracker.com/id?1023344http://securitytracker.com/id?1023345http://www.debian.org/security/2009/dsa-1956http://www.mozilla.org/security/announce/2009/mfsa2009-70.htmlhttp://www.novell.com/linux/security/advisories/2009_63_firefox.htmlhttp://www.securityfocus.com/bid/37349http://www.securityfocus.com/bid/37365http://www.ubuntu.com/usn/USN-873-1http://www.ubuntu.com/usn/USN-874-1http://www.vupen.com/english/advisories/2009/3547https://bugzilla.mozilla.org/show_bug.cgi?id=522430https://bugzilla.redhat.com/show_bug.cgi?id=546724https://exchange.xforce.ibmcloud.com/vulnerabilities/54803https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11568https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8489https://rhn.redhat.com/errata/RHSA-2009-1674.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00995.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg01034.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg01041.htmlhttp://secunia.com/advisories/37699http://secunia.com/advisories/37704http://secunia.com/advisories/37785http://secunia.com/advisories/37813http://secunia.com/advisories/37856http://secunia.com/advisories/37881http://securitytracker.com/id?1023344http://securitytracker.com/id?1023345http://www.debian.org/security/2009/dsa-1956http://www.mozilla.org/security/announce/2009/mfsa2009-70.htmlhttp://www.novell.com/linux/security/advisories/2009_63_firefox.htmlhttp://www.securityfocus.com/bid/37349http://www.securityfocus.com/bid/37365http://www.ubuntu.com/usn/USN-873-1http://www.ubuntu.com/usn/USN-874-1http://www.vupen.com/english/advisories/2009/3547https://bugzilla.mozilla.org/show_bug.cgi?id=522430https://bugzilla.redhat.com/show_bug.cgi?id=546724https://exchange.xforce.ibmcloud.com/vulnerabilities/54803https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11568https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8489https://rhn.redhat.com/errata/RHSA-2009-1674.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00995.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg01034.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg01041.html
2009-12-17
Published