Security Advisory

CVE-2009-3984

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-12-17 17:00:00
Last updated 2024-08-07 06:45:50
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body.