CVE Vulnerabilities

CVE-2009-3988

Published: Feb 22, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*3.0.17 (including)
FirefoxMozilla3.0 (including)3.0 (including)
FirefoxMozilla3.0.1 (including)3.0.1 (including)
FirefoxMozilla3.0.2 (including)3.0.2 (including)
FirefoxMozilla3.0.3 (including)3.0.3 (including)
FirefoxMozilla3.0.4 (including)3.0.4 (including)
FirefoxMozilla3.0.5 (including)3.0.5 (including)
FirefoxMozilla3.0.6 (including)3.0.6 (including)
FirefoxMozilla3.0.7 (including)3.0.7 (including)
FirefoxMozilla3.0.8 (including)3.0.8 (including)
FirefoxMozilla3.0.9 (including)3.0.9 (including)
FirefoxMozilla3.0.10 (including)3.0.10 (including)
FirefoxMozilla3.0.11 (including)3.0.11 (including)
FirefoxMozilla3.0.12 (including)3.0.12 (including)
FirefoxMozilla3.0.13 (including)3.0.13 (including)
FirefoxMozilla3.0.14 (including)3.0.14 (including)
FirefoxMozilla3.0.15 (including)3.0.15 (including)
FirefoxMozilla3.5 (including)3.5 (including)
FirefoxMozilla3.5.1 (including)3.5.1 (including)
FirefoxMozilla3.5.2 (including)3.5.2 (including)
FirefoxMozilla3.5.3 (including)3.5.3 (including)
FirefoxMozilla3.5.4 (including)3.5.4 (including)
FirefoxMozilla3.5.5 (including)3.5.5 (including)
FirefoxMozilla3.5.6 (including)3.5.6 (including)
FirefoxMozilla3.5.7 (including)3.5.7 (including)
SeamonkeyMozilla2.0 (including)2.0 (including)
SeamonkeyMozilla2.0-alpha_1 (including)2.0-alpha_1 (including)
SeamonkeyMozilla2.0-alpha_2 (including)2.0-alpha_2 (including)
SeamonkeyMozilla2.0-alpha_3 (including)2.0-alpha_3 (including)
SeamonkeyMozilla2.0-beta_1 (including)2.0-beta_1 (including)
SeamonkeyMozilla2.0-beta_2 (including)2.0-beta_2 (including)
SeamonkeyMozilla2.0-rc1 (including)2.0-rc1 (including)
SeamonkeyMozilla2.0-rc2 (including)2.0-rc2 (including)
Red Hat Enterprise Linux 4RedHatfirefox-0:3.0.18-1.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.0.18-1.el5_4*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.0.18-1.el5_4*
FirefoxUbuntudapper*
FirefoxUbuntuupstream*
Mozilla-thunderbirdUbuntudapper*
SeamonkeyUbuntuhardy*
SeamonkeyUbuntuintrepid*
SeamonkeyUbuntujaunty*
SeamonkeyUbuntukarmic*
SeamonkeyUbuntulucid*
SeamonkeyUbuntuupstream*
ThunderbirdUbuntuupstream*
Xulrunner-1.9Ubuntuhardy*
Xulrunner-1.9Ubuntuintrepid*
Xulrunner-1.9Ubuntujaunty*
Xulrunner-1.9Ubuntuupstream*
Xulrunner-1.9.1Ubuntujaunty*
Xulrunner-1.9.1Ubuntukarmic*
Xulrunner-1.9.1Ubuntuupstream*

References