CVE-2009-3988
Summary
| CVE | CVE-2009-3988 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-02-22 13:00:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 3.0 | All | All | All |
| Application | Mozilla | Firefox | 3.0.1 | All | All | All |
| Application | Mozilla | Firefox | 3.0.10 | All | All | All |
| Application | Mozilla | Firefox | 3.0.11 | All | All | All |
| Application | Mozilla | Firefox | 3.0.12 | All | All | All |
| Application | Mozilla | Firefox | 3.0.13 | All | All | All |
| Application | Mozilla | Firefox | 3.0.14 | All | All | All |
| Application | Mozilla | Firefox | 3.0.15 | All | All | All |
| Application | Mozilla | Firefox | 3.0.2 | All | All | All |
| Application | Mozilla | Firefox | 3.0.3 | All | All | All |
| Application | Mozilla | Firefox | 3.0.4 | All | All | All |
| Application | Mozilla | Firefox | 3.0.5 | All | All | All |
| Application | Mozilla | Firefox | 3.0.6 | All | All | All |
| Application | Mozilla | Firefox | 3.0.7 | All | All | All |
| Application | Mozilla | Firefox | 3.0.8 | All | All | All |
| Application | Mozilla | Firefox | 3.0.9 | All | All | All |
| Application | Mozilla | Firefox | 3.5 | All | All | All |
| Application | Mozilla | Firefox | 3.5.1 | All | All | All |
| Application | Mozilla | Firefox | 3.5.2 | All | All | All |
| Application | Mozilla | Firefox | 3.5.3 | All | All | All |
| Application | Mozilla | Firefox | 3.5.4 | All | All | All |
| Application | Mozilla | Firefox | 3.5.5 | All | All | All |
| Application | Mozilla | Firefox | 3.5.6 | All | All | All |
| Application | Mozilla | Firefox | 3.5.7 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Seamonkey | 2.0 | All | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_2 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | alpha_3 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | beta_1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | beta_2 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | rc1 | All | All |
| Application | Mozilla | Seamonkey | 2.0 | rc2 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [SECURITY] Fedora 12 Update: galeon-2.0.7-20.fc12 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| USN-895-1: Firefox 3.0 and Xulrunner 1.9 vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Support / Security / Advisories / / MDVSA-2010:042 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| 504862 – (CVE-2009-3988) XSS due to window.dialogArguments accessible cross-domain (MSVR-09-0047 / ZDI-CAN-535) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Debian -- Security Information -- DSA-1999-1 xulrunner | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [SECURITY] Fedora 12 Update: seamonkey-2.0.3-1.fc12 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| USN-896-1: Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Mozilla Firefox Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SUSE update for MozillaFirefox and seamonkey - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [security-announce] SUSE Security Announcement: Mozilla Firefox (SUSE-SA | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [SECURITY] Fedora 11 Update: epiphany-extensions-2.26.1-10.fc11 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| MFSA 2010-04: XSS due to window.dialogArguments being readable cross-domain | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.