CVE-2009-3375
29.10.2009, 14:30
content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 3.0 |
mozilla | firefox | 3.0:alpha |
mozilla | firefox | 3.0:beta2 |
mozilla | firefox | 3.0:beta5 |
mozilla | firefox | 3.0.1 |
mozilla | firefox | 3.0.2 |
mozilla | firefox | 3.0.3 |
mozilla | firefox | 3.0.4 |
mozilla | firefox | 3.0.5 |
mozilla | firefox | 3.0.6 |
mozilla | firefox | 3.0.7 |
mozilla | firefox | 3.0.8 |
mozilla | firefox | 3.0.9 |
mozilla | firefox | 3.0.10 |
mozilla | firefox | 3.0.11 |
mozilla | firefox | 3.0.12 |
mozilla | firefox | 3.0.13 |
mozilla | firefox | 3.5 |
mozilla | firefox | 3.5.1 |
mozilla | firefox | 3.5.2 |
mozilla | firefox | 3.5.3 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
firefox-3.0 |
| ||||||||||
firefox-3.5 |
| ||||||||||
xulrunner-1.9 |
| ||||||||||
xulrunner-1.9.1 |
|
Common Weakness Enumeration
References