Description
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1649-1 | New iceweasel packages fix several vulnerabilities |
Debian DSA |
DSA-1669-1 | New xulrunner packages fix several vulnerabilities |
Debian DSA |
DSA-1697-1 | New iceape packages fix several vulnerabilities |
EUVD |
EUVD-2008-3823 | Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823. |
Ubuntu USN |
USN-645-1 | Firefox and xulrunner vulnerabilities |
Ubuntu USN |
USN-645-2 | Firefox vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T09:53:00.308Z
Reserved: 2008-08-27T00:00:00.000Z
Link: CVE-2008-3837
No data.
Status : Modified
Published: 2008-09-24T20:37:04.517
Modified: 2026-04-23T00:35:47.467
Link: CVE-2008-3837
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN