CVE Vulnerabilities

CVE-2008-3837

Published: Sep 24, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*2.0.0.17 (excluding)
FirefoxMozilla3.0 (including)3.0.2 (excluding)
SeamonkeyMozilla*1.1.12 (excluding)
Red Hat Enterprise Linux 2.1RedHatseamonkey-0:1.0.9-0.20.el2*
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.24.el3*
Red Hat Enterprise Linux 4RedHatfirefox-0:3.0.2-3.el4*
Red Hat Enterprise Linux 4RedHatdevhelp-0:0.10-0.10.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-26.el4*
Red Hat Enterprise Linux 5RedHatdevhelp-0:0.12-19.el5*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.0.2-3.el5*
Red Hat Enterprise Linux 5RedHatnss-0:3.12.1.1-1.el5*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.0.2-5.el5*
Red Hat Enterprise Linux 5RedHatyelp-0:2.16.0-21.el5*
FirefoxUbuntudapper*
FirefoxUbuntudevel*
FirefoxUbuntufeisty*
FirefoxUbuntugutsy*
FirefoxUbuntuhardy*
FirefoxUbuntulucid*
FirefoxUbuntumaverick*
FirefoxUbuntunatty*
FirefoxUbuntuupstream*
Firefox-3.0Ubuntugutsy*
Firefox-3.0Ubuntuhardy*
Firefox-3.0Ubuntuintrepid*
Firefox-3.0Ubuntujaunty*
Firefox-3.0Ubuntuupstream*
IceapeUbuntugutsy*
SeamonkeyUbuntudevel*
SeamonkeyUbuntuhardy*
SeamonkeyUbuntuintrepid*
SeamonkeyUbuntujaunty*
SeamonkeyUbuntukarmic*
SeamonkeyUbuntulucid*
SeamonkeyUbuntumaverick*
SeamonkeyUbuntunatty*
SeamonkeyUbuntuupstream*
XulrunnerUbuntufeisty*
XulrunnerUbuntugutsy*
XulrunnerUbuntuhardy*
XulrunnerUbuntuintrepid*
XulrunnerUbuntujaunty*
XulrunnerUbuntukarmic*
Xulrunner-1.9Ubuntugutsy*
Xulrunner-1.9Ubuntuhardy*
Xulrunner-1.9Ubuntuintrepid*
Xulrunner-1.9Ubuntujaunty*
Xulrunner-1.9Ubuntuupstream*

References