4.3
CVSSv2

CVE-2009-1311

Published: 22/04/2009 Updated: 30/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Mozilla Firefox prior to 3.0.9 and SeaMonkey prior to 1.1.17 allow user-assisted remote malicious users to obtain sensitive information via a web page with an embedded frame, which causes POST data from an outer page to be sent to the inner frame's URL during a SAVEMODE_FILEONLY save of the inner frame.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 0.4

mozilla firefox 0.5

mozilla firefox 0.7

mozilla firefox 0.9.2

mozilla firefox 1.0

mozilla firefox 1.0.3

mozilla firefox 1.5.0.11

mozilla firefox 1.5.0.10

mozilla firefox 1.5.4

mozilla firefox 1.5.1

mozilla firefox 1.8

mozilla firefox 1.5.8

mozilla firefox 2.0.0.18

mozilla firefox 2.0.0.21

mozilla firefox 2.0.0.16

mozilla firefox 2.0

mozilla firefox 2.0.0.4

mozilla firefox 2.0.0.8

mozilla firefox 2.0_.9

mozilla firefox 3.0.1

mozilla firefox 3.0.5

mozilla firefox 3.0

mozilla seamonkey 1.0.3

mozilla firefox 0.6

mozilla firefox 0.6.1

mozilla firefox 0.7.1

mozilla firefox 1.0.2

mozilla firefox 1.0.5

mozilla firefox 1.5

mozilla firefox 1.5.0.6

mozilla firefox 1.5.2

mozilla firefox 1.5.0.8

mozilla firefox 2.0.0.12

mozilla firefox 2.0.0.10

mozilla firefox 2.0.0.15

mozilla firefox 2.0.0.20

mozilla firefox 2.0.0.9

mozilla firefox 2.0_.1

mozilla firefox 2.0_.10

mozilla firefox 2.0_8

mozilla seamonkey 1.0.6

mozilla seamonkey 1.0.7

mozilla seamonkey 1.1

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.5

mozilla seamonkey 1.1.3

mozilla seamonkey 1.5.0.10

mozilla firefox 1.5.0.1

mozilla firefox

mozilla firefox 0.1

mozilla firefox 0.10

mozilla firefox 0.8

mozilla firefox 0.9.1

mozilla firefox 0.9

mozilla firefox 0.9_rc

mozilla firefox 1.0.4

mozilla firefox 1.0.7

mozilla firefox 1.0.6

mozilla firefox 1.5.7

mozilla firefox 1.5.6

mozilla firefox 1.5.0.9

mozilla firefox 1.5.0.7

mozilla firefox 2.0.0.13

mozilla firefox 2.0.0.1

mozilla firefox 2.0.0.17

mozilla firefox 2.0.0.19

mozilla firefox 2.0.0.7

mozilla firefox 2.0_.4

mozilla firefox 2.0_.5

mozilla firefox 3.0.6

mozilla firefox 3.0.4

mozilla firefox 3.0.2

mozilla seamonkey 1.0

mozilla seamonkey 1.0.8

mozilla seamonkey 1.0.9

mozilla seamonkey 1.1.2

mozilla seamonkey 1.1.13

mozilla seamonkey 1.1.8

mozilla firefox 0.10.1

mozilla firefox 0.2

mozilla firefox 0.3

mozilla firefox 0.9.3

mozilla firefox 1.0.1

mozilla firefox 1.0.8

mozilla firefox 1.5.0.3

mozilla firefox 1.5.5

mozilla firefox 1.5.3

mozilla seamonkey 1.0.4

mozilla seamonkey 1.0.5

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.4

mozilla seamonkey 1.1.9

mozilla seamonkey 1.1.15

mozilla seamonkey

mozilla firefox 2.0.0.11

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.3

mozilla firefox 2.0.0.2

mozilla firefox 2.0.0.6

mozilla firefox 2.0.0.5

mozilla firefox 2.0_.6

mozilla firefox 2.0_.7

mozilla firefox 3.0.3

mozilla firefox 3.0.7

mozilla seamonkey 1.0.1

mozilla seamonkey 1.0.2

mozilla seamonkey 1.1.10

mozilla seamonkey 1.0.99

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.11

mozilla seamonkey 1.1.6

mozilla seamonkey 1.1.7

Vendor Advisories

Several flaws were discovered in the browser engine If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program (CVE-2009-1302, CVE-2009-1303, CVE-2009-1304, CVE-2009-1305) ...
Synopsis Critical: seamonkey security update Type/Severity Security Advisory: Critical Topic Updated seamonkey packages that fix several security issues are nowavailable for Red Hat Enterprise Linux 21, 3, and 4This update has been rated as having critical security impact by the RedHat Security Response T ...
Synopsis Critical: firefox security update Type/Severity Security Advisory: Critical Topic Updated firefox packages that fix several security issues are now availablefor Red Hat Enterprise Linux 4 and 5This update has been rated as having critical security impact by the RedHat Security Response Team ...
Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-0652 Moxie Marlinspike discovered that Unicode box drawing characters inside of internationalised domai ...
Mozilla Foundation Security Advisory 2009-21 POST data sent to wrong site when saving web page with embedded frame Announced April 21, 2009 Reporter Paolo Amadini Impact Low Products Firefox, SeaMonkey Fixed in ...

References

CWE-200http://www.mozilla.org/security/announce/2009/mfsa2009-21.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=471962http://www.securitytracker.com/id?1022097http://secunia.com/advisories/34758https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.htmlhttp://secunia.com/advisories/34894http://www.redhat.com/support/errata/RHSA-2009-0436.htmlhttp://secunia.com/advisories/34843http://www.securityfocus.com/bid/34656http://rhn.redhat.com/errata/RHSA-2009-0437.htmlhttp://secunia.com/advisories/34844http://www.vupen.com/english/advisories/2009/1125http://secunia.com/advisories/35065http://www.mandriva.com/security/advisories?name=MDVSA-2009:111http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://secunia.com/advisories/35042http://www.debian.org/security/2009/dsa-1797http://secunia.com/advisories/35561http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.htmlhttp://secunia.com/advisories/35882https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.htmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7235https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6222https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6200https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10939https://usn.ubuntu.com/764-1/https://usn.ubuntu.com/764-1/https://nvd.nist.gov