Vulnerability Description
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 2.0.0.17 |
| Mozilla | Seamonkey | < 1.1.12 |
| Debian | Debian Linux | 4.0 |
| Canonical | Ubuntu Linux | 6.06 |
References
- http://download.novell.com/Download?buildid=WZXONb-tqBw~Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00005.htmlThird Party Advisory
- http://secunia.com/advisories/31984Third Party Advisory
- http://secunia.com/advisories/31985Third Party Advisory
- http://secunia.com/advisories/31987Third Party Advisory
- http://secunia.com/advisories/32010Third Party Advisory
- http://secunia.com/advisories/32011Third Party Advisory
- http://secunia.com/advisories/32012Third Party Advisory
- http://secunia.com/advisories/32042Third Party Advisory
- http://secunia.com/advisories/32044Third Party Advisory
- http://secunia.com/advisories/32089Third Party Advisory
- http://secunia.com/advisories/32095Third Party Advisory
- http://secunia.com/advisories/32096Third Party Advisory
- http://secunia.com/advisories/32144Third Party Advisory
- http://secunia.com/advisories/32185Third Party Advisory
FAQ
What is CVE-2008-3837?
CVE-2008-3837 is a vulnerability with a CVSS score of 9.3 (HIGH). Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or uns...
How severe is CVE-2008-3837?
CVE-2008-3837 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-3837?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Seamonkey, Debian Debian Linux, Canonical Ubuntu Linux.