CVE detail
CVE-2009-1307 — CVE-2009-1307
Published 2009-04-22 · Modified 2026-06-16 · Vendor mozilla · Product firefox · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0218
EPSS probability
exploitation probability, 30d
81.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References