SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-3985

Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the…

MEDIUM 6.8EPSS 2.54%

Does this matter?

Lower severity and a low EPSS score (2.54%). Track it; it rarely justifies an emergency change on its own.

Description

Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
2.54% probability · 84th percentile
CISA KEV
Not listed
Affected
mozilla/firefox · mozilla/seamonkey
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.