CVE-2009-1840
12.06.2009, 21:30
Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 ≤ 3.0.10 |
mozilla | firefox | 3.0 |
mozilla | firefox | 3.0:alpha |
mozilla | firefox | 3.0:beta2 |
mozilla | firefox | 3.0:beta5 |
mozilla | firefox | 3.0.1 |
mozilla | firefox | 3.0.2 |
mozilla | firefox | 3.0.3 |
mozilla | firefox | 3.0.4 |
mozilla | firefox | 3.0.5 |
mozilla | firefox | 3.0.6 |
mozilla | firefox | 3.0.7 |
mozilla | firefox | 3.0.8 |
mozilla | firefox | 3.0.9 |
mozilla | firefox | 3.0beta5:beta5 |
mozilla | firefox | 3.1:beta1 |
mozilla | seamonkey | * |
mozilla | thunderbird | * |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||||||||||
thunderbird |
| ||||||||||||||||||
xulrunner |
| ||||||||||||||||||
xulrunner-1.9 |
| ||||||||||||||||||
xulrunner-1.9.1 |
|
Common Weakness Enumeration
References