Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-0777 | First vendor Publication | 2009-03-04 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 5.8 | Attack Range | Network |
Cvss Impact Score | 4.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0777 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-20 | Improper Input Validation |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:11222 | |||
Oval ID: | oval:org.mitre.oval:def:11222 | ||
Title: | Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks. | ||
Description: | Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2009-0777 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:22504 | |||
Oval ID: | oval:org.mitre.oval:def:22504 | ||
Title: | ELSA-2009:0315: firefox security update (Critical) | ||
Description: | Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2009:0315-01 CVE-2009-0040 CVE-2009-0771 CVE-2009-0772 CVE-2009-0773 CVE-2009-0774 CVE-2009-0775 CVE-2009-0776 CVE-2009-0777 | Version: | 37 |
Platform(s): | Oracle Linux 5 | Product(s): | firefox xulrunner |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:29381 | |||
Oval ID: | oval:org.mitre.oval:def:29381 | ||
Title: | RHSA-2009:0315 -- firefox security update (Critical) | ||
Description: | An updated firefox package that fixes various security issues is now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having critical security impact by the Red Hat Security Response Team. Mozilla Firefox is an open source Web browser. Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code as the user running Firefox. (CVE-2009-0040, CVE-2009-0771, CVE-2009-0772, CVE-2009-0773, CVE-2009-0774, CVE-2009-0775) | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2009:0315 CESA-2009:0315-CentOS 5 CVE-2009-0040 CVE-2009-0771 CVE-2009-0772 CVE-2009-0773 CVE-2009-0774 CVE-2009-0775 CVE-2009-0776 CVE-2009-0777 | Version: | 3 |
Platform(s): | Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 4 CentOS Linux 5 | Product(s): | firefox xulrunner |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:6039 | |||
Oval ID: | oval:org.mitre.oval:def:6039 | ||
Title: | Mozilla Thunderbird Phishing Vulnerability | ||
Description: | Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2009-0777 | Version: | 6 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista | Product(s): | Mozilla Thunderbird |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:6157 | |||
Oval ID: | oval:org.mitre.oval:def:6157 | ||
Title: | Mozilla Firefox Phishing Vulnerability | ||
Description: | Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2009-0777 | Version: | 4 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista | Product(s): | Mozilla Firefox |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:6229 | |||
Oval ID: | oval:org.mitre.oval:def:6229 | ||
Title: | Mozilla Seamonkey Phishing Vulnerability | ||
Description: | Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2009-0777 | Version: | 2 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista | Product(s): | Mozilla Seamonkey |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:7435 | |||
Oval ID: | oval:org.mitre.oval:def:7435 | ||
Title: | Mozilla Firefox, Thunderbird and Seamonkey Phishing Vulnerability | ||
Description: | Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2009-0777 | Version: | 19 |
Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows 8 Microsoft Windows 8.1 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows Server 2012 Microsoft Windows Server 2012 R2 | Product(s): | Mozilla Firefox Mozilla Thunderbird Mozilla Seamonkey |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2011-08-09 | Name : CentOS Update for firefox CESA-2009:0315 centos4 i386 File : nvt/gb_CESA-2009_0315_firefox_centos4_i386.nasl |
2011-08-09 | Name : CentOS Update for firefox CESA-2009:0315 centos5 i386 File : nvt/gb_CESA-2009_0315_firefox_centos5_i386.nasl |
2009-10-11 | Name : SLES11: Security update for MozillaFirefox File : nvt/sles11_MozillaFirefox.nasl |
2009-03-20 | Name : Mandrake Security Advisory MDVSA-2009:075 (firefox) File : nvt/mdksa_2009_075.nasl |
2009-03-20 | Name : SuSE Security Advisory SUSE-SA:2009:012 (MozillaFirefox) File : nvt/suse_sa_2009_012.nasl |
2009-03-13 | Name : Fedora Core 9 FEDORA-2009-2421 (firefox) File : nvt/fcore_2009_2421.nasl |
2009-03-13 | Name : Fedora Core 10 FEDORA-2009-2422 (firefox) File : nvt/fcore_2009_2422.nasl |
2009-03-13 | Name : CentOS Security Advisory CESA-2009:0315 (firefox) File : nvt/ovcesa2009_0315.nasl |
2009-03-10 | Name : Mozilla Firefox Multiple Vulnerabilities Mar-09 (Linux) File : nvt/gb_firefox_mult_vuln_mar09_lin.nasl |
2009-03-10 | Name : Mozilla Firefox Multiple Vulnerabilities Mar-09 (Win) File : nvt/gb_firefox_mult_vuln_mar09_win.nasl |
2009-03-10 | Name : Mozilla Seamonkey Multiple Vulnerabilities Mar-09 (Linux) File : nvt/gb_seamonkey_mult_vuln_mar09_lin.nasl |
2009-03-10 | Name : Mozilla Seamonkey Multiple Vulnerabilities Mar-09 (Win) File : nvt/gb_seamonkey_mult_vuln_mar09_win.nasl |
2009-03-10 | Name : Mozilla Thunderbird Multiple Vulnerabilities Mar-09 (Linux) File : nvt/gb_thunderbird_mult_vuln_mar09_lin.nasl |
2009-03-10 | Name : Mozilla Thunderbird Multiple Vulnerabilities Mar-09 (Win) File : nvt/gb_thunderbird_mult_vuln_mar09_win.nasl |
2009-03-07 | Name : RedHat Security Advisory RHSA-2009:0315 File : nvt/RHSA_2009_0315.nasl |
2009-03-07 | Name : Ubuntu USN-728-1 (xulrunner-1.9) File : nvt/ubuntu_728_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
52452 | Mozilla Multiple Products Location Bar Invisible Character Decoding Spoofing ... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2009-0315.nasl - Type : ACT_GATHER_INFO |
2013-01-08 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201301-01.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20090304_firefox_on_SL4_x.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_MozillaFirefox-090319.nasl - Type : ACT_GATHER_INFO |
2009-07-21 | Name : The remote openSUSE host is missing a security update. File : suse_11_0_MozillaFirefox-090312.nasl - Type : ACT_GATHER_INFO |
2009-07-21 | Name : The remote openSUSE host is missing a security update. File : suse_11_1_MozillaFirefox-090312.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Fedora host is missing one or more security updates. File : fedora_2009-2422.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2009-075.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-728-1.nasl - Type : ACT_GATHER_INFO |
2009-03-09 | Name : The remote Fedora host is missing one or more security updates. File : fedora_2009-2421.nasl - Type : ACT_GATHER_INFO |
2009-03-08 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2009-0315.nasl - Type : ACT_GATHER_INFO |
2009-03-05 | Name : The remote Windows host contains a web browser that is affected by multiple v... File : mozilla_firefox_307.nasl - Type : ACT_GATHER_INFO |
2009-03-05 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2009-0315.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2025-02-07 01:11:57 |
|
2024-11-28 23:12:00 |
|
2024-11-28 12:18:25 |
|
2024-11-01 01:11:23 |
|
2024-10-22 12:11:21 |
|
2024-08-02 12:11:09 |
|
2024-08-02 01:03:02 |
|
2024-02-10 01:10:09 |
|
2024-02-02 01:10:40 |
|
2024-02-01 12:03:00 |
|
2023-09-05 12:09:58 |
|
2023-09-05 01:02:52 |
|
2023-09-02 12:10:04 |
|
2023-09-02 01:02:53 |
|
2023-08-12 12:11:45 |
|
2023-08-12 01:02:52 |
|
2023-08-11 12:10:06 |
|
2023-08-11 01:02:59 |
|
2023-08-06 12:09:42 |
|
2023-08-06 01:02:54 |
|
2023-08-04 12:09:48 |
|
2023-08-04 01:02:56 |
|
2023-07-14 12:09:46 |
|
2023-07-14 01:02:54 |
|
2023-03-29 01:11:14 |
|
2023-03-28 12:03:00 |
|
2022-10-11 12:08:41 |
|
2022-10-11 01:02:43 |
|
2021-05-04 12:09:13 |
|
2021-04-22 01:09:33 |
|
2020-10-14 01:04:25 |
|
2020-10-03 01:04:23 |
|
2020-05-29 01:04:01 |
|
2020-05-23 01:40:07 |
|
2020-05-23 00:23:26 |
|
2019-06-25 12:02:33 |
|
2019-01-30 12:02:51 |
|
2018-07-13 01:03:02 |
|
2017-11-22 12:02:56 |
|
2017-09-29 09:24:06 |
|
2017-08-17 09:22:29 |
|
2016-06-28 17:36:37 |
|
2016-04-26 18:40:35 |
|
2014-02-17 10:49:04 |
|
2013-05-10 23:45:28 |
|