CVE-2009-1839

Mozilla Firefox < 3.0.10 - Access Control

Title source: rule

Description

Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jordi Chancel · htmllocalmultiple
https://www.exploit-db.com/exploits/10544

Scores

EPSS 0.1516
EPSS Percentile 94.6%

Details

CWE
CWE-264
Status published
Products (13)
mozilla/firefox 3.0 (4 CPE variants)
mozilla/firefox 3.0.1
mozilla/firefox 3.0.2
mozilla/firefox 3.0.3
mozilla/firefox 3.0.4
mozilla/firefox 3.0.5
mozilla/firefox 3.0.6
mozilla/firefox 3.0.7
mozilla/firefox 3.0.8
mozilla/firefox 3.0.9
... and 3 more
Published Jun 12, 2009
Tracked Since Feb 18, 2026