Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2009-12-17T17:00:00

Updated: 2024-08-07T06:45:50.919Z

Reserved: 2009-11-19T00:00:00

Link: CVE-2009-3985

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2009-12-17T17:30:00.530

Modified: 2017-09-19T01:29:52.703

Link: CVE-2009-3985

cve-icon Redhat

Severity : Moderate

Publid Date: 2009-12-15T00:00:00Z

Links: CVE-2009-3985 - Bugzilla