CVE-2009-3375

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
VendorProductVersion
mozillafirefox
3.0
mozillafirefox
3.0:alpha
mozillafirefox
3.0:beta2
mozillafirefox
3.0:beta5
mozillafirefox
3.0.1
mozillafirefox
3.0.2
mozillafirefox
3.0.3
mozillafirefox
3.0.4
mozillafirefox
3.0.5
mozillafirefox
3.0.6
mozillafirefox
3.0.7
mozillafirefox
3.0.8
mozillafirefox
3.0.9
mozillafirefox
3.0.10
mozillafirefox
3.0.11
mozillafirefox
3.0.12
mozillafirefox
3.0.13
mozillafirefox
3.5
mozillafirefox
3.5.1
mozillafirefox
3.5.2
mozillafirefox
3.5.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox-3.0
karmic
dne
jaunty
Fixed 3.0.15+nobinonly-0ubuntu0.9.04.1
released
intrepid
Fixed 3.0.15+nobinonly-0ubuntu0.8.10.1
released
hardy
Fixed 3.0.15+nobinonly-0ubuntu0.8.04.1
released
dapper
dne
firefox-3.5
karmic
Fixed 3.5.4+nobinonly-0ubuntu0.9.10.1
released
jaunty
Fixed 3.5.4+nobinonly-0ubuntu0.9.04.1
released
intrepid
dne
hardy
dne
dapper
dne
xulrunner-1.9
karmic
dne
jaunty
Fixed 1.9.0.15+nobinonly-0ubuntu0.9.04.1
released
intrepid
Fixed 1.9.0.15+nobinonly-0ubuntu0.8.10.1
released
hardy
Fixed 1.9.0.15+nobinonly-0ubuntu0.8.04.1
released
dapper
dne
xulrunner-1.9.1
karmic
Fixed 1.9.1.4+nobinonly-0ubuntu0.9.10.1
released
jaunty
Fixed 1.9.1.4+nobinonly-0ubuntu0.9.04.3
released
intrepid
dne
hardy
dne
dapper
dne
Common Weakness Enumeration