« Back to list

CVE-2009-1840

Status: ModifiedHigh (9.3)—

Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (3)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2009-1840",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-06-12T21:30:00.420",
  "references": [
    {
      "url": "http://osvdb.org/55158",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/35331",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/35415",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/35431",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/35439",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/35440",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/35468",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.debian.org/security/2009/dsa-1820",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:141",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.mozilla.org/security/announce/2009/mfsa2009-31.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/35326",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securitytracker.com/id?1022379",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/1572",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=477979",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=503582",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51076",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9448",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://rhn.redhat.com/errata/RHSA-2009-1095.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://osvdb.org/55158",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/35331",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/35415",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/35431",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/35439",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/35440",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/35468",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2009/dsa-1820",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:141",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mozilla.org/security/announce/2009/mfsa2009-31.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/35326",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1022379",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/1572",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=477979",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=503582",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51076",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9448",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://rhn.redhat.com/errata/RHSA-2009-1095.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a \"web bug\" in an e-mail message, or web script or an advertisement in a web page."
    },
    {
      "lang": "es",
      "value": "Mozilla Firefox anterior a v3.0.11, Thunderbird, y SeaMonkey no comprueban la politica de contenidos antes de cargar un fichero de secuencia de comandos que este en un documento XUL, lo que permite a atacantes remotos evitar las restricciones de acceso previstas a través de un documento HTML manipulado, como se demostró mediante un \"web bug\" en un mensaje de correo electrónico, o secuencias de comandos web o un anuncio en una página."
    }
  ],
  "lastModified": "2026-06-16T23:08:10.350",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E05337C3-04A1-4403-84BE-78FCDF83448D",
              "versionEndIncluding": "3.0.10"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "412DF091-7604-4110-87A0-3488116A97E5"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:3.0:alpha:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A1DE6AC-C6AA-4B27-AC21-3293E5357A7E"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:3.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13AAF607-AEEE-4FAF-BE63-73B1D951EF52"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:3.0:beta5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20139741-10B1-4E4B-8D5F-A715042049C4"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:3.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "11E07FED-ABDB-4B0A-AB2E-4CBF1EAC4301"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:3.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9A6558F1-9E0D-4107-909A-8EF4BC8A9C2F"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:3.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63DF3D65-C992-44CF-89B4-893526C6242E"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:3.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9024117-2E8B-4240-9E21-CC501F3879B5"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:3.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FBC3CAD3-2F54-4E32-A0C9-0D826C45AC23"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:3.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52624B41-AB34-40AD-8709-D9646B618AB0"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:3.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "917E9856-9556-4FD6-A834-858F8837A6B4"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:3.0.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98BBD74D-930C-4D80-A91B-0D61347BAA63"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:3.0.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAF2E696-883D-4DE5-8B79-D8E5D9470253"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:3.0beta5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "880CAA7D-398A-4B26-9754-FD188CE9729D"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:3.1:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F72BFD4-000D-4B07-8261-C9F6839AD150"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "138701FB-929A-4683-B41F-CB014ACFE44A"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5C8E657-3049-4462-98F6-296C60BC8C5C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}