CVE-2009-3014
31.08.2009, 16:30
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location HTTP response header or (2) specifying the content of a Location HTTP response header.
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 ≤ 3.0.13 |
mozilla | firefox | 3.0.1 |
mozilla | firefox | 3.0.2 |
mozilla | firefox | 3.0.3 |
mozilla | firefox | 3.0.4 |
mozilla | firefox | 3.0.5 |
mozilla | firefox | 3.0.6 |
mozilla | firefox | 3.0.7 |
mozilla | firefox | 3.0.8 |
mozilla | firefox | 3.0.9 |
mozilla | firefox | 3.0.10 |
mozilla | firefox | 3.0.11 |
mozilla | firefox | 3.0.12 |
mozilla | firefox | 3.5 |
mozilla | firefox | 3.6:a1_pre |
mozilla | firefox | 3.7:a1_pre |
mozilla | mozilla | 𝑥 ≤ 1.7 |
mozilla | mozilla | 0.8 |
mozilla | mozilla | 0.9.2 |
mozilla | mozilla | 0.9.2.1 |
mozilla | mozilla | 0.9.3 |
mozilla | mozilla | 0.9.4 |
mozilla | mozilla | 0.9.4.1 |
mozilla | mozilla | 0.9.5 |
mozilla | mozilla | 0.9.6 |
mozilla | mozilla | 0.9.7 |
mozilla | mozilla | 0.9.8 |
mozilla | mozilla | 0.9.9 |
mozilla | mozilla | 0.9.35 |
mozilla | mozilla | 0.9.48 |
mozilla | mozilla | 1.0 |
mozilla | mozilla | 1.0:rc1 |
mozilla | mozilla | 1.0:rc2 |
mozilla | mozilla | 1.0:rc3 |
mozilla | mozilla | 1.0.1 |
mozilla | mozilla | 1.0.2 |
mozilla | mozilla | 1.1 |
mozilla | mozilla | 1.1:alpha |
mozilla | mozilla | 1.1:beta |
mozilla | mozilla | 1.2 |
mozilla | mozilla | 1.2:alpha |
mozilla | mozilla | 1.2:beta |
mozilla | mozilla | 1.2.1 |
mozilla | mozilla | 1.3 |
mozilla | mozilla | 1.3.1 |
mozilla | mozilla | 1.4 |
mozilla | mozilla | 1.4:alpha |
mozilla | mozilla | 1.4:beta |
mozilla | mozilla | 1.4.1 |
mozilla | mozilla | 1.4.2 |
mozilla | mozilla | 1.4.4 |
mozilla | mozilla | 1.5 |
mozilla | mozilla | 1.5:alpha |
mozilla | mozilla | 1.5:rc1 |
mozilla | mozilla | 1.5:rc2 |
mozilla | mozilla | 1.5.1 |
mozilla | mozilla | 1.6 |
mozilla | mozilla | 1.6:alpha |
mozilla | mozilla | 1.6:beta |
mozilla | seamonkey | 1.1.17 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
firefox |
| ||||||||||
seamonkey |
| ||||||||||
xulrunner-1.9 |
| ||||||||||
xulrunner-1.9.1 |
| ||||||||||
xulrunner-1.9.2 |
|
References