CVE-2009-1839 describes a vulnerability in Mozilla Firefox 3 prior to version 3.0.11 where an incorrect principal is associated with file: URLs loaded via the location bar. This flaw allows user-assisted remote attackers to bypass access restrictions and read local files through a crafted HTML document, a technique known as "file-URL-to-file-URL scripting." The vulnerability has a CVSS score of 5.4, indicating a medium severity, with high attack complexity and a critical impact on confidentiality. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry (EDB-10544) for location bar spoofing exists, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.0.10CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.0:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.0:alpha:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.0:beta2:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.0:beta5:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:C/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.