MEDIUM · 4.3

CVE-2009-3007

Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a vic...

Vulnerability Description

Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
FlockFlock2.5.1
MozillaFirefox3.5.1
MozillaSeamonkey1.1.7

References

FAQ

What is CVE-2009-3007?

CVE-2009-3007 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a vic...

How severe is CVE-2009-3007?

CVE-2009-3007 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-3007?

Check the references section above for vendor advisories and patch information. Affected products include: Flock Flock, Mozilla Firefox, Mozilla Seamonkey.