peter bassill · operator
$ cve CVE-2009-1839 JSON

CVE-2009-1839 EXPLOIT

5.4
MEDIUM · CVSS 2.0 · EPSS 7.1% (pctl 94)

Patch early

A public exploit exists.

Description

Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.

Scoring

CVSS5.4 (MEDIUM, v2.0)
VectorAV:N/AC:H/Au:N/C:C/I:N/A:N
EPSS7.12% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2009-06-12
Last modified2026-06-16

Affected (1)

VendorProduct
mozillafirefox

Public exploits

SourceTitleDate
exploit-dbMozilla Firefox - Location Bar Spoofing2009-12-18

References

→ the Explorer  ·  watch your stack  ·  NVD