[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-3985Date: (C)2009-12-17   (M)2024-03-27


Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1023342
SECTRACK-1023343
BID-37349
BID-37370
SECUNIA-37699
SECUNIA-37704
SECUNIA-37785
SECUNIA-37813
SECUNIA-37856
SECUNIA-37881
ADV-2009-3547
DSA-1956
FEDORA-2009-13333
FEDORA-2009-13362
FEDORA-2009-13366
RHSA-2009:1674
SUSE-SA:2009:063
USN-873-1
USN-874-1
firefox-documentlocation-spoofing(54808)
http://www.mozilla.org/security/announce/2009/mfsa2009-69.html
https://bugzilla.mozilla.org/show_bug.cgi?id=514232
https://bugzilla.redhat.com/show_bug.cgi?id=546726
oval:org.mitre.oval:def:8480
oval:org.mitre.oval:def:9911

CPE    136
cpe:/a:mozilla:firefox:1.5:beta2
cpe:/a:mozilla:firefox:1.5:beta1
cpe:/a:mozilla:firefox:0.8
cpe:/a:mozilla:firefox:0.7
...
OVAL    43
oval:org.secpod.oval:def:700441
oval:org.secpod.oval:def:700445
oval:org.secpod.oval:def:200593
oval:org.secpod.oval:def:400098
...

© SecPod Technologies