CVE-2009-1840 describes a critical vulnerability in Mozilla Firefox before version 3.0.11, Thunderbird, and SeaMonkey, where the applications fail to enforce content policy before loading script files into XUL documents. This oversight allows remote attackers to bypass security restrictions, potentially through crafted HTML in emails (web bugs) or malicious web content. With a CVSS score of 9.3 (Critical), this vulnerability has a network attack vector, medium attack complexity, and could lead to complete compromise of confidentiality, integrity, and availability. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) is available and there's no evidence of active exploitation or significant community discussion, the high FAUCET Risk Score of 75/100 indicates its potential severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.0.10CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.0:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.0:alpha:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.0:beta2:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.0:beta5:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.