Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade seamonkeyUpgrade seamonkey-dom-inspectorUpgrade seamonkey-mailUpgrade thunderbirdUpgrade nss-toolsUpgrade nspr-develUpgrade firefoxUpgrade seamonkey-nssUpgrade nsprUpgrade nssUpgrade nss-pkcs11-develUpgrade seamonkey-chatUpgrade xulrunner-devel-unstableUpgrade nss-develUpgrade xulrunner-develUpgrade xulrunnerUpgrade seamonkey-js-debuggerUpgrade seamonkey-nspr-develUpgrade seamonkey-nsprUpgrade seamonkey-nss-develUpgrade seamonkey-devel | Dec 1, 2016 | Dec 17, 2008 |
| Freebsd | — | Upgrade linux-firefoxUpgrade linux-thunderbirdUpgrade firefoxUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade thunderbird | Dec 10, 2025 | Dec 19, 2008 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/firefox-bin.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/thunderbird.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/seamonkey-bin.Upgrade www-client/seamonkey.Upgrade mail-client/mozilla-thunderbird.Upgrade net-libs/xulrunner.Upgrade dev-libs/nss.Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox.Upgrade www-client/mozilla-firefox.Upgrade www-client/icecat. | Oct 30, 2017 | Dec 17, 2008 |
| Mfsa2008 65 | — | Upgrade to Mozilla Firefox version 3.0.5 | Jun 14, 2012 | Dec 17, 2008 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.14 | Feb 3, 2012 | Dec 17, 2008 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.19 | Feb 22, 2012 | Dec 17, 2008 |
| Oracle_linux | — | Upgrade nss-develUpgrade xulrunnerUpgrade xulrunner-devel-unstableUpgrade nssUpgrade nss-toolsUpgrade firefoxUpgrade nsprUpgrade nss-pkcs11-develUpgrade xulrunner-develUpgrade nspr-devel | Oct 16, 2024 | Dec 17, 2008 |
| Suse | — | Upgrade MozillaThunderbirdUpgrade python-xpcom190Upgrade mozilla-xulrunner181-l10n-32bitUpgrade seamonkey-ircUpgrade mozilla-csUpgrade mozilla-xulrunner190-translationsUpgrade mozilla-xulrunner190-translations-64bitUpgrade mozilla-mailUpgrade MozillaThunderbird-develUpgrade epiphanyUpgrade mozilla-huUpgrade mozillaUpgrade seamonkey-venkmanUpgrade mozilla-xulrunner181Upgrade mozilla-xulrunner190-translations-32bitUpgrade seamonkey-mailUpgrade mozilla-xulrunner181-32bitUpgrade seamonkey-spellcheckerUpgrade gecko-sdkUpgrade seamonkeyUpgrade mozilla-xulrunner190-64bitUpgrade MozillaThunderbird-translationsUpgrade mozilla-calendarUpgrade mozilla-venkmanUpgrade seamonkey-dom-inspectorUpgrade mozilla-dom-inspectorUpgrade mozilla-xulrunner190-develUpgrade mozilla-xulrunner181-develUpgrade mozilla-xulrunner181-l10nUpgrade mozilla-xulrunner190-gnomevfsUpgrade mozilla-deatUpgrade mozilla-develUpgrade mozilla-xulrunner190Upgrade mozilla-xulrunner190-gnomevfs-64bitUpgrade mozilla-xulrunner190-32bitUpgrade mozilla-ircUpgrade mozilla-xulrunner181-64bitUpgrade mozilla-xulrunner190-gnomevfs-32bitUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations | Feb 17, 2015 | Dec 17, 2008 |
| Ubuntu | — | Upgrade xulrunner-1.9Upgrade firefox-3.0Upgrade abrowserUpgrade mozilla-thunderbirdUpgrade firefoxUpgrade thunderbird | Nov 8, 2024 | Dec 17, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub