Aller au contenu
Appaloosa Scout

Vulnérabilité · NVD

CVE-2009-1306

N/A

EN The jar: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not follow the Content-Disposition header of the inner URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via an uploaded .jar file with a "Content-Disposition: attachment" designation.

EPSS 1.33% au-dessus de la médiane percentile 68.5%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

Configurations CPE vulnérables (1)
Vendor Produit Versions
mozilla thunderbird
Toutes plateformes (wildcard)
Voir sur NVD ↗ Advisory · www.mozilla.org