Loading...
Loading...
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.
December 17, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2009-3985
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.