CVE-2009-0776: Infoleak
nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0776?
CVE-2009-0776 has been classified as a moderate severity vulnerability due to its potential to bypass the same-origin policy.
How do I fix CVE-2009-0776?
To fix CVE-2009-0776, upgrade to Mozilla Firefox version 3.0.7 or later, Thunderbird version 2.0.0.21 or later, or SeaMonkey version 1.1.15 or later.
Which applications are affected by CVE-2009-0776?
CVE-2009-0776 affects Mozilla Firefox versions up to 3.0.6, Thunderbird versions up to 2.0.0.20, and SeaMonkey versions up to 1.1.14.
What type of attack does CVE-2009-0776 enable?
CVE-2009-0776 enables remote attackers to bypass the same-origin policy and read XML data from another domain through cross-domain redirects.
When was CVE-2009-0776 disclosed?
CVE-2009-0776 was disclosed in March 2009 and is a well-known vulnerability impacting several Mozilla applications.