Back

MEDIUM

Firefox cross-origin data theft through document.getSelection()

Published Oct 29, 2009

Description

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 29, 2009
Updated Aug 7, 2024
Reserved Sep 24, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Oct 27, 2009