Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade seamonkey-nsprUpgrade seamonkey-js-debuggerUpgrade xulrunner-develUpgrade nss-develUpgrade xulrunner-devel-unstableUpgrade nssUpgrade seamonkey-chatUpgrade nss-pkcs11-develUpgrade seamonkey-develUpgrade seamonkey-nspr-develUpgrade xulrunnerUpgrade seamonkey-nss-develUpgrade seamonkey-dom-inspectorUpgrade thunderbirdUpgrade nspr-develUpgrade nsprUpgrade nss-toolsUpgrade seamonkey-mailUpgrade seamonkey-nssUpgrade firefoxUpgrade seamonkey | Dec 1, 2016 | Dec 17, 2008 |
| Freebsd | — | Upgrade linux-thunderbirdUpgrade linux-firefoxUpgrade firefoxUpgrade thunderbirdUpgrade seamonkeyUpgrade linux-seamonkey | Dec 10, 2025 | Dec 19, 2008 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade net-libs/xulrunner-bin.Upgrade www-client/firefox.Upgrade dev-libs/nss.Upgrade www-client/mozilla-firefox.Upgrade net-libs/xulrunner.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/seamonkey.Upgrade mail-client/thunderbird-bin.Upgrade www-client/icecat.Upgrade www-client/seamonkey-bin. | Oct 30, 2017 | Dec 17, 2008 |
| Mfsa2008 65 | — | Upgrade to Mozilla Firefox version 3.0.5 | Jun 14, 2012 | Dec 17, 2008 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.14 | Feb 3, 2012 | Dec 17, 2008 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.19 | Feb 22, 2012 | Dec 17, 2008 |
| Oracle_linux | — | Upgrade nss-pkcs11-develUpgrade nspr-develUpgrade nsprUpgrade firefoxUpgrade xulrunner-develUpgrade nssUpgrade xulrunner-devel-unstableUpgrade nss-toolsUpgrade nss-develUpgrade xulrunner | Oct 16, 2024 | Dec 17, 2008 |
| Suse | — | Upgrade mozilla-xulrunner190Upgrade MozillaFirefoxUpgrade mozilla-xulrunner190-gnomevfs-64bitUpgrade mozilla-venkmanUpgrade mozilla-deatUpgrade MozillaFirefox-translationsUpgrade mozilla-xulrunner190-64bitUpgrade mozilla-xulrunner181-64bitUpgrade mozilla-develUpgrade MozillaThunderbird-translationsUpgrade mozilla-xulrunner181-l10nUpgrade mozilla-ircUpgrade mozilla-xulrunner190-develUpgrade seamonkey-dom-inspectorUpgrade mozilla-calendarUpgrade mozilla-xulrunner190-gnomevfsUpgrade mozilla-xulrunner190-32bitUpgrade gecko-sdkUpgrade mozilla-dom-inspectorUpgrade mozilla-xulrunner181-develUpgrade mozilla-xulrunner190-gnomevfs-32bitUpgrade seamonkeyUpgrade mozilla-xulrunner190-translationsUpgrade mozilla-xulrunner190-translations-32bitUpgrade mozilla-xulrunner190-translations-64bitUpgrade seamonkey-ircUpgrade MozillaThunderbirdUpgrade mozilla-huUpgrade seamonkey-mailUpgrade MozillaThunderbird-develUpgrade seamonkey-venkmanUpgrade mozilla-xulrunner181-l10n-32bitUpgrade mozilla-xulrunner181-32bitUpgrade epiphanyUpgrade mozillaUpgrade mozilla-csUpgrade seamonkey-spellcheckerUpgrade python-xpcom190Upgrade mozilla-mailUpgrade mozilla-xulrunner181 | Feb 17, 2015 | Dec 17, 2008 |
| Ubuntu | — | Upgrade xulrunner-1.9Upgrade mozilla-thunderbirdUpgrade firefox-3.0Upgrade firefoxUpgrade abrowserUpgrade thunderbird | Nov 8, 2024 | Dec 17, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub