Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-3987

Опубликовано: 17 дек. 2009
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 7.8

Описание

The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects.

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

not-affected

intrepid

not-affected

jaunty

not-affected

karmic

DNE

upstream

released

3.0.16

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

DNE

intrepid

DNE

jaunty

not-affected

karmic

not-affected

upstream

released

3.5.6

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

not-affected

intrepid

not-affected

jaunty

not-affected

karmic

not-affected

upstream

released

2.0.1

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

not-affected

intrepid

not-affected

jaunty

not-affected

karmic

DNE

upstream

released

1.9.0.16

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

DNE

intrepid

DNE

jaunty

not-affected

karmic

not-affected

upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 72%
0.00812
Низкий

7.8 High

CVSS2

Связанные уязвимости

redhat
почти 16 лет назад

The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects.

nvd
почти 16 лет назад

The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects.

debian
почти 16 лет назад

The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3 ...

github
больше 3 лет назад

The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects.

EPSS

Процентиль: 72%
0.00812
Низкий

7.8 High

CVSS2

Уязвимость CVE-2009-3987