CVE-2008-3837: Critical severity firefox vulnerability
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3837?
CVE-2008-3837 is considered a medium severity vulnerability that allows remote attackers to manipulate windows during user interaction.
How do I fix CVE-2008-3837?
To fix CVE-2008-3837, upgrade Mozilla Firefox to versions 2.0.0.17 or later and 3.0.2 or later, or update SeaMonkey to version 1.1.12 or later.
Which browsers are affected by CVE-2008-3837?
CVE-2008-3837 affects Mozilla Firefox versions before 2.0.0.17 and 3.x before 3.0.2, as well as SeaMonkey versions before 1.1.12.
What type of attacks can CVE-2008-3837 facilitate?
CVE-2008-3837 can facilitate user-assisted attacks such as forced file downloads or other unintended drag-and-drop actions.
Is there a specific environment that is vulnerable to CVE-2008-3837?
CVE-2008-3837 is particularly documented in environments running outdated versions of Mozilla Firefox and SeaMonkey on various Linux distributions.