CVE Vulnerabilities

CVE-2009-1840

Published: Jun 12, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
1.8 MODERATE
AV:A/AC:H/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a web bug in an e-mail message, or web script or an advertisement in a web page.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*3.0.10 (including)
FirefoxMozilla3.0 (including)3.0 (including)
FirefoxMozilla3.0-alpha (including)3.0-alpha (including)
FirefoxMozilla3.0-beta2 (including)3.0-beta2 (including)
FirefoxMozilla3.0-beta5 (including)3.0-beta5 (including)
FirefoxMozilla3.0.1 (including)3.0.1 (including)
FirefoxMozilla3.0.2 (including)3.0.2 (including)
FirefoxMozilla3.0.3 (including)3.0.3 (including)
FirefoxMozilla3.0.4 (including)3.0.4 (including)
FirefoxMozilla3.0.5 (including)3.0.5 (including)
FirefoxMozilla3.0.6 (including)3.0.6 (including)
FirefoxMozilla3.0.7 (including)3.0.7 (including)
FirefoxMozilla3.0.8 (including)3.0.8 (including)
FirefoxMozilla3.0.9 (including)3.0.9 (including)
FirefoxMozilla3.0beta5 (including)3.0beta5 (including)
FirefoxMozilla3.1-beta1 (including)3.1-beta1 (including)
SeamonkeyMozilla**
ThunderbirdMozilla**
Red Hat Enterprise Linux 4RedHatfirefox-0:3.0.11-4.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.0.11-2.el5_3*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.0.11-3.el5_3*
FirefoxUbuntudapper*
FirefoxUbuntuhardy*
ThunderbirdUbuntudevel*
ThunderbirdUbuntuhardy*
ThunderbirdUbuntuintrepid*
ThunderbirdUbuntujaunty*
ThunderbirdUbuntukarmic*
ThunderbirdUbuntulucid*
ThunderbirdUbuntumaverick*
ThunderbirdUbuntunatty*
ThunderbirdUbuntuoneiric*
XulrunnerUbuntuhardy*
XulrunnerUbuntuintrepid*
XulrunnerUbuntujaunty*
XulrunnerUbuntukarmic*
Xulrunner-1.9Ubuntuhardy*
Xulrunner-1.9Ubuntuintrepid*
Xulrunner-1.9Ubuntujaunty*
Xulrunner-1.9.1Ubuntujaunty*
Xulrunner-1.9.1Ubuntukarmic*

References