CVE-2009-1839

Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:C/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
mozillafirefox
𝑥
≤ 3.0.10
mozillafirefox
3.0
mozillafirefox
3.0:alpha
mozillafirefox
3.0:beta2
mozillafirefox
3.0:beta5
mozillafirefox
3.0.1
mozillafirefox
3.0.2
mozillafirefox
3.0.3
mozillafirefox
3.0.4
mozillafirefox
3.0.5
mozillafirefox
3.0.6
mozillafirefox
3.0.7
mozillafirefox
3.0.8
mozillafirefox
3.0.9
mozillafirefox
3.0beta5:beta5
mozillafirefox
3.1:beta1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
karmic
dne
jaunty
dne
intrepid
dne
hardy
not-affected
dapper
ignored
xulrunner-1.9
karmic
dne
jaunty
Fixed 1.9.0.11+build2+nobinonly-0ubuntu0.9.04.1
released
intrepid
Fixed 1.9.0.11+build2+nobinonly-0ubuntu0.8.10.2
released
hardy
Fixed 1.9.0.11+build2+nobinonly-0ubuntu0.8.04.1
released
dapper
dne
xulrunner-1.9.1
karmic
Fixed 1.9.1~rc2+nobinonly-0ubuntu1
released
jaunty
Fixed 1.9.1+nobinonly-0ubuntu0.9.04.1
released
intrepid
dne
hardy
dne
dapper
dne
Common Weakness Enumeration
References