CVE-2009-3014: XSS

Published Aug 31, 2009
·
Updated

Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location HTTP response header or (2) specifying the content of a Location HTTP response header.

Affected Software

60 affected components
Mozilla Mozilla=1.4.2
Mozilla Mozilla=0.9.5
Mozilla Mozilla=1.0-rc3
Mozilla Firefox=3.0.7
Mozilla Mozilla=0.9.35
Mozilla Firefox=3.0.9
Mozilla Mozilla=0.9.3
Mozilla Mozilla=1.0.1
Mozilla Mozilla<=1.7
Mozilla Firefox=3.0.8
Mozilla Mozilla=0.9.48
Mozilla SeaMonkey=1.1.17
Mozilla Mozilla=1.2.1
Mozilla Mozilla=1.5-rc2
Mozilla Mozilla=1.0-rc1
Mozilla Firefox=3.5
Mozilla Firefox=3.0.4
Mozilla Mozilla=1.2-alpha
Mozilla Firefox=3.7-a1_pre
Mozilla Firefox<=3.0.13
Mozilla Firefox=3.0.5
Mozilla Mozilla=0.9.7
Mozilla Mozilla=1.1-beta
Mozilla Mozilla=1.0-rc2
Mozilla Firefox=3.6-a1_pre
Mozilla Mozilla=1.6-beta
Mozilla Mozilla=0.9.2.1
Mozilla Mozilla=1.4.1
Mozilla Mozilla=1.4-beta
Mozilla Mozilla=1.2
Mozilla Mozilla=0.9.2
Mozilla Firefox=3.0.10
Mozilla Mozilla=1.5-alpha
Mozilla Mozilla=1.4.4
Mozilla Mozilla=1.5-rc1
Mozilla Mozilla=1.3
Mozilla Mozilla=1.2-beta
Mozilla Firefox=3.0.12
Mozilla Firefox=3.0.3
Mozilla Mozilla=1.0
Mozilla Mozilla=0.9.8
Mozilla Mozilla=1.4
Mozilla Mozilla=1.5
Mozilla Firefox=3.0.6
Mozilla Mozilla=0.9.4
Mozilla Firefox=3.0.1
Mozilla Mozilla=1.4-alpha
Mozilla Mozilla=0.9.6
Mozilla Firefox=3.0.2
Mozilla Mozilla=1.5.1
Mozilla Mozilla=1.1
Mozilla Mozilla=1.1-alpha
Mozilla Mozilla=0.9.4.1
Mozilla Mozilla=0.8
Mozilla Mozilla=1.0.2
Mozilla Mozilla=1.3.1
Mozilla Mozilla=1.6-alpha
Mozilla Mozilla=0.9.9
Mozilla Mozilla=1.6
Mozilla Firefox=3.0.11

Event History

Aug 31, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2009-3014?

CVE-2009-3014 has a medium severity level as it allows for possible cross-site scripting attacks.

2

How do I fix CVE-2009-3014?

To mitigate CVE-2009-3014, users should update to the latest version of Mozilla Firefox or SeaMonkey that addresses this vulnerability.

3

Which versions are affected by CVE-2009-3014?

CVE-2009-3014 affects Mozilla Firefox versions 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre along with SeaMonkey 1.1.17 and earlier versions of Mozilla 1.7.x.

4

What type of attacks can exploit CVE-2009-3014?

CVE-2009-3014 can be exploited for cross-site scripting (XSS) attacks if users are tricked into navigating to a malicious link.

5

Are there any workarounds for CVE-2009-3014 until a fix is applied?

As a workaround for CVE-2009-3014, users should avoid clicking on suspicious links or Javascript: URIs in unknown emails or web pages.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203