Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary web script or HTML via vectors involving XBL JavaScript bindings and remote stylesheets, as exploited in the wild by a March 2009 eBay listing.
References
Link Providers
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html cve-icon cve-icon
http://secunia.com/advisories/34758 cve-icon cve-icon
http://secunia.com/advisories/34780 cve-icon cve-icon
http://secunia.com/advisories/34843 cve-icon cve-icon
http://secunia.com/advisories/34894 cve-icon cve-icon
http://secunia.com/advisories/35042 cve-icon cve-icon
http://secunia.com/advisories/35065 cve-icon cve-icon
http://secunia.com/advisories/35536 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1 cve-icon cve-icon
http://www.debian.org/security/2009/dsa-1797 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2009:111 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2009:141 cve-icon cve-icon
http://www.mozilla.org/security/announce/2009/mfsa2009-18.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2009-0436.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2009-1126.html cve-icon cve-icon
http://www.securityfocus.com/bid/34656 cve-icon cve-icon
http://www.securitytracker.com/id?1022097 cve-icon cve-icon
http://www.theregister.co.uk/2009/03/08/ebay_scam_wizardy/ cve-icon cve-icon
http://www.ubuntu.com/usn/usn-782-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/1125 cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=481558 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2009-1308 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10428 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6173 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6185 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6296 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7285 cve-icon cve-icon
https://usn.ubuntu.com/764-1/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2009-1308 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2009-04-22T18:00:00

Updated: 2024-08-07T05:04:49.602Z

Reserved: 2009-04-16T00:00:00

Link: CVE-2009-1308

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2009-04-22T18:30:00.327

Modified: 2023-02-13T02:20:06.773

Link: CVE-2009-1308

cve-icon Redhat

Severity : Low

Publid Date: 2009-04-21T00:00:00Z

Links: CVE-2009-1308 - Bugzilla