CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.0. It affects Firefox. It may be remotely exploitable.
CVE
CVE-2009-3988
Severity
MEDIUM
CVSS
5
EPSS
2.15%
Firefox
Original NVD Description
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.