CVE-2009-3988

CVSS v2.0 5 (Medium)
50% Progress
EPSS 1.35 % (86th)
1.35% Progress
Affected Products 2
Advisories 8

Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.

Weaknesses
CWE-264
Permissions, Privileges, and Access Controls
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2010-02-22 13:00:01
(14 years ago)
Updated Date
2017-09-19 01:29:52
(7 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 3.0.17 and prior versions cpe:2.3:a:mozilla:firefox <= 3.0.17
  Mozilla Firefox 3.0 cpe:2.3:a:mozilla:firefox:3.0
  Mozilla Firefox 3.0.1 cpe:2.3:a:mozilla:firefox:3.0.1
  Mozilla Firefox 3.0.2 cpe:2.3:a:mozilla:firefox:3.0.2
  Mozilla Firefox 3.0.3 cpe:2.3:a:mozilla:firefox:3.0.3
  Mozilla Firefox 3.0.4 cpe:2.3:a:mozilla:firefox:3.0.4
  Mozilla Firefox 3.0.5 cpe:2.3:a:mozilla:firefox:3.0.5
  Mozilla Firefox 3.0.6 cpe:2.3:a:mozilla:firefox:3.0.6
  Mozilla Firefox 3.0.7 cpe:2.3:a:mozilla:firefox:3.0.7
  Mozilla Firefox 3.0.8 cpe:2.3:a:mozilla:firefox:3.0.8
  Mozilla Firefox 3.0.9 cpe:2.3:a:mozilla:firefox:3.0.9
  Mozilla Firefox 3.0.10 cpe:2.3:a:mozilla:firefox:3.0.10
  Mozilla Firefox 3.0.11 cpe:2.3:a:mozilla:firefox:3.0.11
  Mozilla Firefox 3.0.12 cpe:2.3:a:mozilla:firefox:3.0.12
  Mozilla Firefox 3.0.13 cpe:2.3:a:mozilla:firefox:3.0.13
  Mozilla Firefox 3.0.14 cpe:2.3:a:mozilla:firefox:3.0.14
  Mozilla Firefox 3.0.15 cpe:2.3:a:mozilla:firefox:3.0.15
  Mozilla Firefox 3.5 cpe:2.3:a:mozilla:firefox:3.5
  Mozilla Firefox 3.5.1 cpe:2.3:a:mozilla:firefox:3.5.1
  Mozilla Firefox 3.5.2 cpe:2.3:a:mozilla:firefox:3.5.2
  Mozilla Firefox 3.5.3 cpe:2.3:a:mozilla:firefox:3.5.3
  Mozilla Firefox 3.5.4 cpe:2.3:a:mozilla:firefox:3.5.4
  Mozilla Firefox 3.5.5 cpe:2.3:a:mozilla:firefox:3.5.5
  Mozilla Firefox 3.5.6 cpe:2.3:a:mozilla:firefox:3.5.6
  Mozilla Firefox 3.5.7 cpe:2.3:a:mozilla:firefox:3.5.7
  Mozilla Seamonkey 2.0 cpe:2.3:a:mozilla:seamonkey:2.0
  Mozilla Seamonkey 2.0 Alpha 1 cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1
  Mozilla Seamonkey 2.0 Alpha 2 cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2
  Mozilla Seamonkey 2.0 Alpha 3 cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3
  Mozilla Seamonkey 2.0 Beta 1 cpe:2.3:a:mozilla:seamonkey:2.0:beta_1
  Mozilla Seamonkey 2.0 Beta 2 cpe:2.3:a:mozilla:seamonkey:2.0:beta_2
  Mozilla Seamonkey 2.0 Rc1 cpe:2.3:a:mozilla:seamonkey:2.0:rc1
  Mozilla Seamonkey 2.0 Rc2 cpe:2.3:a:mozilla:seamonkey:2.0:rc2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...