CVE-2009-0357
Published Feb 4, 2009
Last updated 7 years ago
Overview
- Description
- Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EAF11F35-A1E8-452C-8EC8-58C7B41617D3", "versionEndIncluding": "3.0.5" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7C7AA88B-638A-451A-B235-A1A1444BE417" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9C01AD7C-8470-47AB-B8AE-670E3A381E89" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E43F2F1-9252-4B44-8A61-D05305915A5F" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3BB9D48B-DC7B-4D92-BB26-B6DE629A2506" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A360D595-A829-4DDE-932E-9995626917E5" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E9B5349-FAA7-4CDA-9533-1AD1ACDFAC4E" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "07243837-C353-4C25-A5B1-4DA32807E97D" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B832C034-F793-415F-BFC8-D97A18BA6BC7" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83CD1A13-66CB-49CC-BD84-5D8334DB774A" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "93C142C5-3A85-432B-80D6-2E7B1B4694F4" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2434FCE7-A50B-4527-9970-C7224B31141C" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "429ECA02-DBCD-45FB-942C-CA4BC1BC8A72" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B5F0DC80-5473-465C-9D7F-9589F1B78E12" }, { "criteria": "cpe:2.3:a:mozilla:firefox:0.9.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "567FF916-7DE0-403C-8528-7931A43E0D18" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5A545A77-2198-4685-A87F-E0F2DAECECF6" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.0:preview_release:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "438AACF8-006F-4522-853F-30DBBABD8C15" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "778FAE0C-A5CF-4B67-93A9-1A803E3E699F" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E7447185-7509-449D-8907-F30A42CF7EB5" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0EDBAC37-9D08-44D1-B279-BC6ACF126CAF" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3FFF89FA-2020-43CC-BACD-D66117B3DD26" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "834BB391-5EB5-43A8-980A-D305EDAE6FA7" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9A38AD88-BAA6-4FBE-885B-69E951BD1EFE" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B500EE6C-99DB-49A3-A1F1-AFFD7FE28068" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F2938F2-A801-45E5-8E06-BE03DE03C8A7" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ABB88E86-6E83-4A59-9266-8B98AA91774D" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D6BF5B1-86D1-47FE-9D9C-735718F94874" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "84D15CE0-69DF-4EFD-801E-96A4D6AABEDB" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CEE203DE-6C0E-4FDE-9C3A-0E73430F17DA" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F2F38886-C25A-4C6B-93E7-36461405BA99" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C65D2670-F37F-48CB-804A-D35BB1C27D9F" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DE8E5194-7B34-4802-BDA6-6A86EB5EDE05" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FABA5F56-99F7-4F8F-9CC1-5B0B2EB72922" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2917BD67-CE81-4B94-B241-D4A9DDA60319" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A524A94E-F19B-42B9-AA8E-171751C339AA" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F71436CF-F756-44E0-8E69-6951F6B3E54A" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "582EE839-B83F-4908-9780-D0C92DC44FD0" }, { "criteria": "cpe:2.3:a:mozilla:firefox:1.5.0.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "824369CF-00A0-434E-94BC-71CA1317012C" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3487FA64-BE04-42CA-861E-3DAC097D7D32" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A956C036-1E47-49B2-A971-69868A510B75" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5AA254D-D41E-464F-9E2A-A950F08C6946" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B05D2655-6641-42BE-9793-30005AC9D40D" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F3D956DC-C73B-439F-8D79-8239207CC76F" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "57E2C7E7-56C0-466C-BB08-5EB43922C4F9" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "462E135A-5616-46CC-A9C0-5A7A0526ACC6" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6121F9C1-F4DF-4AAB-9E51-AC1592AA5639" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "58D44634-A0B5-4F05-8983-B08D392EC742" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EB3AC3D3-FDD7-489F-BDCF-BDB55DF33A8B" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4105171B-9C90-4ABF-B220-A35E7BA9EE40" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20985549-DB24-4B69-9D40-208A47AE658E" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "43A13026-416F-4308-8A1B-E989BD769E12" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "612B015E-9F96-4CE6-83E4-23848FD609E5" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E391619-0967-43E1-8CBC-4D54F72A85C2" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0544D626-E269-4677-9B05-7DAB23BD103B" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C95F7B2C-80FC-4DF2-9680-F74634DCE3E6" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "863C140E-DC15-4A88-AB8A-8AEF9F4B8164" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "38CD049A-5333-4FF7-AD34-6B74E19BADCB" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0066576D-D66A-4B59-B5C3-471EEBEE8B9A" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.17:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "60ED6DAA-9194-4829-BC1A-00F04BE7930A" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.18:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13BEB9A6-EFD5-4793-9603-84DB84F1CF7D" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.19:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "461163C6-4CA8-4BA9-95A1-136E612CBA6B" }, { "criteria": "cpe:2.3:a:mozilla:firefox:2.0.0.20:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "275E9D96-1290-44AB-BF9B-E9E4A803F593" }, { "criteria": "cpe:2.3:a:mozilla:firefox:3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "412DF091-7604-4110-87A0-3488116A97E5" }, { "criteria": "cpe:2.3:a:mozilla:firefox:3.0:alpha:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7A1DE6AC-C6AA-4B27-AC21-3293E5357A7E" }, { "criteria": "cpe:2.3:a:mozilla:firefox:3.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "13AAF607-AEEE-4FAF-BE63-73B1D951EF52" }, { "criteria": "cpe:2.3:a:mozilla:firefox:3.0:beta5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20139741-10B1-4E4B-8D5F-A715042049C4" }, { "criteria": "cpe:2.3:a:mozilla:firefox:3.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "11E07FED-ABDB-4B0A-AB2E-4CBF1EAC4301" }, { "criteria": "cpe:2.3:a:mozilla:firefox:3.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9A6558F1-9E0D-4107-909A-8EF4BC8A9C2F" }, { "criteria": "cpe:2.3:a:mozilla:firefox:3.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "63DF3D65-C992-44CF-89B4-893526C6242E" }, { "criteria": "cpe:2.3:a:mozilla:firefox:3.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A9024117-2E8B-4240-9E21-CC501F3879B5" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "547B206A-36E7-4602-8046-8366BC556AA5", "versionEndIncluding": "1.1.13" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "09E18FC0-0C8C-4FA1-85B9-B868D00F002F" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0:alpha:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A97B6E1-EABA-4977-A3FC-64DF0392AA95" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CB01A97F-ACE1-4A99-8939-6DF8FE5B5E8E" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6521C877-63C9-4B6E-9FC9-1263FFBB7950" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D949DF0A-CBC2-40E1-AE6C-60E6F58D2481" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C5CDA57-1A50-4EDB-80E2-D3EBB44EA653" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "22D33486-4956-4E2C-BA16-FA269A9D02BD" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3104343E-93B6-4D4A-BC95-ED9F7E91FB6A" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "381313EF-DF84-4F66-9962-DE8F45029D79" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A0228476-14E4-443C-BBAE-2C9CD8594DC0" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A803A500-DCE2-44FC-ABEB-A90A1D39D85C" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "022274DE-5251-49C9-B6E5-1D8CEDC34E7D" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B9F84CB7-93F7-4912-BC87-497867B96491" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1:alpha:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8992E9C6-09B3-492E-B7DA-899D5238EC18" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D58B704B-F06E-44C1-BBD1-A090D1E6583A" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "40270FBD-744A-49D9-9FFA-1DCD897210D7" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20E01097-F60A-4FB2-BA47-84A267EE87D6" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F65732F-317B-49A2-B9B0-FA1102B8B45C" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DB430F19-069A-43FD-9097-586D4449D327" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "76AD0439-3BFB-4AD1-8E2C-99D0B099FA8C" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E6D7528-E591-48A6-8165-BE42F8EBF6B6" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BA710423-0075-44B8-9DCB-6380FA974486" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C5521DA3-E6AF-4350-B971-10B4A1C9B1D1" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DDD15752-A253-47B1-BCE0-B55B84B47C9F" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "60B39A9D-44A4-4D7F-9004-C44066BBE277" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F203EC52-2126-4227-AF3B-23857E5BB222" }, { "criteria": "cpe:2.3:a:mozilla:seamonkey:1.1.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E951567B-8402-42EA-AE33-EBA9235A868F" } ], "operator": "OR" } ] } ]