Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade firefoxUpgrade xulrunnerUpgrade xulrunner-develUpgrade xulrunner-devel-unstable | Dec 1, 2016 | Jun 12, 2009 |
| Freebsd | — | Upgrade seamonkeyUpgrade linux-firefoxUpgrade linux-thunderbirdUpgrade thunderbirdUpgrade linux-firefox-develUpgrade linux-seamonkeyUpgrade firefox | Dec 10, 2025 | Jun 12, 2009 |
| Gentoo Linux | — | Upgrade net-libs/xulrunner.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade dev-libs/nss.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/thunderbird-bin.Upgrade www-client/seamonkey.Upgrade www-client/icecat.Upgrade mail-client/thunderbird.Upgrade www-client/firefox.Upgrade www-client/seamonkey-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/firefox-bin. | Oct 30, 2017 | Jun 12, 2009 |
| Mfsa2009 30 | — | Upgrade to Mozilla Firefox version 3.0.11 | Jun 14, 2012 | Jun 12, 2009 |
| Oracle_linux | — | Upgrade firefoxUpgrade xulrunner-develUpgrade xulrunnerUpgrade xulrunner-devel-unstable | Oct 16, 2024 | Jun 12, 2009 |
| Suse | — | Upgrade mozilla-xulrunner190Upgrade mozilla-nss-toolsUpgrade orbit2-32bitUpgrade mozilla-nss-x86Upgrade mozilla-xulrunner191Upgrade mozilla-xulrunner192-translationsUpgrade orbit2Upgrade mozilla-xulrunner192-32bitUpgrade libfreebl3-32bitUpgrade gconf2-x86Upgrade mozilla-xulrunner192-gnomeUpgrade mozilla-nspr-x86Upgrade MozillaFirefox-translationsUpgrade mozilla-xulrunner190-32bitUpgrade mozilla-xulrunner191-gnomevfsUpgrade gconf2Upgrade mozilla-nspr-32bitUpgrade mozilla-nss-32bitUpgrade MozillaFirefoxUpgrade mozilla-xulrunner191-translationsUpgrade mozilla-xulrunner190-gnomevfsUpgrade libidlUpgrade mozilla-xulrunner190-translationsUpgrade mozilla-xulrunner191-32bitUpgrade mozilla-xulrunner191-x86Upgrade libfreebl3Upgrade mozilla-xulrunner192-x86Upgrade libidl-x86Upgrade mozilla-nsprUpgrade MozillaFirefox-branding-SLEDUpgrade mozilla-xulrunner190-x86Upgrade mozilla-xulrunner192Upgrade libidl-32bitUpgrade gconf2-32bitUpgrade libfreebl3-x86Upgrade orbit2-x86Upgrade mozilla-nss | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade firefox-3.0Upgrade xulrunner-1.9Upgrade abrowser | Nov 8, 2024 | Jun 12, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub