Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-2654

Опубликовано: 03 авг. 2009
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 5.8

Описание

Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.

РелизСтатусПримечание
dapper

DNE

devel

released

3.0.13+nobinonly-0ubuntu1
hardy

released

3.0.13+nobinonly-0ubuntu0.8.04.1
intrepid

released

3.0.13+nobinonly-0ubuntu0.8.10.1
jaunty

released

3.0.13+nobinonly-0ubuntu0.9.04.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

released

3.5.2+nobinonly-0ubuntu1
hardy

DNE

intrepid

DNE

jaunty

released

3.5.2+nobinonly-0ubuntu0.9.04.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

released

1.9.0.13+nobinonly-0ubuntu1
hardy

released

1.9.0.13+nobinonly-0ubuntu0.8.04.1
intrepid

released

1.9.0.13+nobinonly-0ubuntu0.8.10.1
jaunty

released

1.9.0.13+nobinonly-0ubuntu0.9.04.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

released

1.9.1.2+nobinonly-0ubuntu2
hardy

DNE

intrepid

DNE

jaunty

released

1.9.1.2+nobinonly-0ubuntu0.9.04.1
upstream

needs-triage

Показывать по

EPSS

Процентиль: 94%
0.13196
Средний

5.8 Medium

CVSS2

Связанные уязвимости

redhat
почти 16 лет назад

Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.

nvd
почти 16 лет назад

Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.

debian
почти 16 лет назад

Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote a ...

github
около 3 лет назад

Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.

oracle-oval
почти 16 лет назад

ELSA-2009-1430: firefox security update (CRITICAL)

EPSS

Процентиль: 94%
0.13196
Средний

5.8 Medium

CVSS2