CVE-2009-1840: Critical severity Mozilla SeaMonkey vulnerability

Published Jun 1, 2009
·
Updated

Mozilla add-on developer and community member Wladimir Palant reported that two key security checks are not being called when loading XUL scripts. The checks which are skipped are intended to verify that content loading policies will not be violated by loading a XUL script. Mozilla code relying on the content policies for security, such as privileged add-ons, could potentially be exploited to run JavaScript with elevated privileges.

Other sources

Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.

Affected Software

18 affected components
Mozilla SeaMonkey
Mozilla Firefox=3.0.7
Mozilla Firefox=3.1-beta1
Mozilla Firefox=3.0.9
Mozilla Firefox=3.0.8
Mozilla Firefox=3.0.4
Mozilla Firefox=3.0.5
Mozilla Firefox=3.0-beta2
Mozilla Thunderbird
Mozilla Firefox=3.0.3
Mozilla Firefox<=3.0.10
Mozilla Firefox=3.0.6
Mozilla Firefox=3.0
Mozilla Firefox=3.0.1
Mozilla Firefox=3.0.2
Mozilla Firefox=3.0beta5
Mozilla Firefox=3.0-beta5
Mozilla Firefox=3.0-alpha

Event History

Jun 1, 2009
Data Sourced
07:19 PM
DescriptionSeverityAffected Software
Jun 12, 2009
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2009-1840?

CVE-2009-1840 is classified as a moderate severity vulnerability.

2

How do I fix CVE-2009-1840?

To fix CVE-2009-1840, you should update your Mozilla Firefox or SeaMonkey to the latest version that addresses this vulnerability.

3

Which software is affected by CVE-2009-1840?

CVE-2009-1840 affects several versions of Mozilla Firefox (3.0.0 to 3.0.10) and Mozilla SeaMonkey.

4

What is the nature of the vulnerability described in CVE-2009-1840?

CVE-2009-1840 involves skipping crucial security checks when loading XUL scripts, potentially violating content loading policies.

5

Is CVE-2009-1840 still a threat today?

While CVE-2009-1840 is a historical vulnerability, using outdated software can put systems at risk, so it is best to update to the latest versions to mitigate any potential risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203