Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary web script or HTML via vectors involving XBL JavaScript bindings and remote stylesheets, as exploited in the wild by a March 2009 eBay listing.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
http://secunia.com/advisories/34758
http://secunia.com/advisories/34780
http://secunia.com/advisories/34843
http://secunia.com/advisories/34894
http://secunia.com/advisories/35042
http://secunia.com/advisories/35065
http://secunia.com/advisories/35536
http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1
http://www.debian.org/security/2009/dsa-1797
http://www.mandriva.com/security/advisories?name=MDVSA-2009:111
http://www.mandriva.com/security/advisories?name=MDVSA-2009:141
http://www.mozilla.org/security/announce/2009/mfsa2009-18.html Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2009-0436.html
http://www.redhat.com/support/errata/RHSA-2009-1126.html
http://www.securityfocus.com/bid/34656
http://www.securitytracker.com/id?1022097
http://www.theregister.co.uk/2009/03/08/ebay_scam_wizardy/
http://www.ubuntu.com/usn/usn-782-1
http://www.vupen.com/english/advisories/2009/1125
https://bugzilla.mozilla.org/show_bug.cgi?id=481558 Exploit
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10428
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6173
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6185
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6296
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7285
https://usn.ubuntu.com/764-1/
https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2009-04-22T18:00:00

Updated: 2018-10-03T20:57:01

Reserved: 2009-04-16T00:00:00


Link: CVE-2009-1308

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2009-04-22T18:30:00.327

Modified: 2023-02-13T02:20:06.773


Link: CVE-2009-1308

JSON object: View

cve-icon Redhat Information

No data.

CWE