KEVIntel
4.3
CVSS
Medium

CVE-2009-1308

PUBLISHED

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary...

Exploited in the wild Remote
Vendor
Mozilla
Product
Firefox, Thunderbird, SeaMonkey
Published
Apr 22, 2009
EPSS

Automate this intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary web script or HTML via vectors involving XBL JavaScript bindings and remote stylesheets, as exploited in the wild by a March 2009 eBay listing.

java

CVSS scores

CVSS v2.0 4.3 Medium

AV:N/AC:M/Au:N/C:N/I:P/A:N

Exploitation status

Exploited in the wild

Recorded 2009-04-22 18:00:00 UTC · CVE

References

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE First 2009-04-22 18:00 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel