CVE-2009-3988: XSS
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3988?
CVE-2009-3988 has been classified as a moderate severity vulnerability.
How do I fix CVE-2009-3988?
To fix CVE-2009-3988, update to Mozilla Firefox version 3.0.18, 3.5.8, or later, or to SeaMonkey version 2.0.3 or later.
What does CVE-2009-3988 expose my system to?
CVE-2009-3988 allows attackers to bypass the Same Origin Policy, leading to potential cross-site scripting (XSS) attacks.
Which versions are affected by CVE-2009-3988?
CVE-2009-3988 affects Mozilla Firefox versions 3.0.1 through 3.0.17 and 3.5.* versions prior to 3.5.8, as well as certain versions of SeaMonkey.
Is there a workaround for CVE-2009-3988 if I cannot update?
There is no specific workaround for CVE-2009-3988 aside from updating to a secure version of the affected software.