CVE-2009-3988
published 2010-02-22CVE-2009-3988: Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in…
PriorityP420medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.15%
80.2th percentile
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.17 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Firefox up to 3.5.7 Same Origin Policy access control (Bug 504862 / Nessus ID 44648)
vuldb·2026-05-01·CVSS 5.0
CVE-2009-3988 [MEDIUM] Mozilla Firefox up to 3.5.7 Same Origin Policy access control (Bug 504862 / Nessus ID 44648)
A vulnerability classified as problematic has been found in Mozilla Firefox. This affects an unknown part of the component Same Origin Policy. The manipulation leads to improper access controls.
This vulnerability is documented as CVE-2009-3988. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
GHSA
GHSA-rjp9-ghg2-39qp: Mozilla Firefox 3
ghsa_unreviewed·2022-05-02
CVE-2009-3988 [MEDIUM] GHSA-rjp9-ghg2-39qp: Mozilla Firefox 3
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.
Ubuntu
Firefox 3.0 and Xulrunner 1.9 vulnerabilities
vendor_ubuntu·2010-02-17·CVSS 10.0
CVE-2010-0159 [CRITICAL] Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Title: Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Summary: Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious website, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-0159)
Orlando Barrera II discovered a flaw in the Web Workers implementation of
Firefox. If a user were tricked into posting to a malicious website, an
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0160)
Alin Rad Pop discovered that Firefox's HTML parser would incorrectly free
memory under certain circumstances. If the bro
Ubuntu
Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
vendor_ubuntu·2010-02-17·CVSS 10.0
CVE-2010-0160 [CRITICAL] Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Title: Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Summary: Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious website, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-0159)
Orlando Barrera II discovered a flaw in the Web Workers implementation of
Firefox. If a user were tricked into posting to a malicious website, an
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2010-0160)
Alin Rad Pop discovered that Firefox's HTML parser would incorrectly free
memory under certain circumstances. If the
Red Hat
Mozilla violation of same-origin policy due to properties set on objects passed to showModalDialog (MFSA 2010-04)
vendor_redhat·2010-02-17·CVSS 5.0
CVE-2009-3988 [MEDIUM] Mozilla violation of same-origin policy due to properties set on objects passed to showModalDialog (MFSA 2010-04)
Mozilla violation of same-origin policy due to properties set on objects passed to showModalDialog (MFSA 2010-04)
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.htmlhttp://secunia.com/advisories/37242http://secunia.com/advisories/38847http://www.debian.org/security/2010/dsa-1999http://www.mandriva.com/security/advisories?name=MDVSA-2010:042http://www.mozilla.org/security/announce/2010/mfsa2010-04.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0112.htmlhttp://www.ubuntu.com/usn/USN-895-1http://www.ubuntu.com/usn/USN-896-1http://www.vupen.com/english/advisories/2010/0405https://bugzilla.mozilla.org/show_bug.cgi?id=504862https://exchange.xforce.ibmcloud.com/vulnerabilities/56362https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8355https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9384http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035367.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035426.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00001.htmlhttp://secunia.com/advisories/37242http://secunia.com/advisories/38847http://www.debian.org/security/2010/dsa-1999http://www.mandriva.com/security/advisories?name=MDVSA-2010:042http://www.mozilla.org/security/announce/2010/mfsa2010-04.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0112.htmlhttp://www.ubuntu.com/usn/USN-895-1http://www.ubuntu.com/usn/USN-896-1http://www.vupen.com/english/advisories/2010/0405https://bugzilla.mozilla.org/show_bug.cgi?id=504862https://exchange.xforce.ibmcloud.com/vulnerabilities/56362https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8355https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9384
2010-02-22
Published