Description
Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1797-1 | New xulrunner packages fix several vulnerabilities |
EUVD |
EUVD-2009-1310 | Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected. |
Ubuntu USN |
USN-764-1 | Firefox and Xulrunner vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T05:04:49.647Z
Reserved: 2009-04-16T00:00:00.000Z
Link: CVE-2009-1312
No data.
Status : Modified
Published: 2009-04-22T18:30:00.407
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-1312
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN