CVE-2009-0777
Last modified
CVE-2009-0777 is a vulnerability of currently unknown severity. Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.. EPSS estimates a 1.50% chance of exploitation in the next 30 days.
Description
Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | <= 3.0.6 |
| Mozilla | Firefox | 1.0 |
| Mozilla | Firefox | 1.0.1 |
| Mozilla | Firefox | 1.0.2 |
| Mozilla | Firefox | 1.0.3 |
| Mozilla | Firefox | 1.0.4 |
| Mozilla | Firefox | 1.0.5 |
| Mozilla | Firefox | 1.0.6 |
| Mozilla | Firefox | 1.0.7 |
| Mozilla | Firefox | 1.0.8 |
| Mozilla | Firefox | 1.5 |
| Mozilla | Firefox | 1.5.0.1 |
| Mozilla | Firefox | 1.5.0.2 |
| Mozilla | Firefox | 1.5.0.3 |
| Mozilla | Firefox | 1.5.0.4 |
| Mozilla | Firefox | 1.5.0.5 |
| Mozilla | Firefox | 1.5.0.6 |
| Mozilla | Firefox | 1.5.0.7 |
| Mozilla | Firefox | 1.5.0.8 |
| Mozilla | Firefox | 1.5.0.9 |
| Mozilla | Firefox | 1.5.0.10 |
| Mozilla | Firefox | 1.5.0.11 |
| Mozilla | Firefox | 1.5.0.12 |
| Mozilla | Firefox | 2.0 |
| Mozilla | Firefox | 2.0.0.1 |
| Mozilla | Firefox | 2.0.0.2 |
| Mozilla | Firefox | 2.0.0.3 |
| Mozilla | Firefox | 2.0.0.4 |
| Mozilla | Firefox | 2.0.0.5 |
| Mozilla | Firefox | 2.0.0.6 |
| Mozilla | Firefox | 2.0.0.7 |
| Mozilla | Firefox | 2.0.0.8 |
| Mozilla | Firefox | 2.0.0.9 |
| Mozilla | Firefox | 2.0.0.10 |
| Mozilla | Firefox | 2.0.0.11 |
| Mozilla | Firefox | 2.0.0.12 |
| Mozilla | Firefox | 2.0.0.13 |
| Mozilla | Firefox | 2.0.0.14 |
| Mozilla | Firefox | 2.0.0.15 |
| Mozilla | Firefox | 2.0.0.16 |
| Mozilla | Firefox | 2.0.0.17 |
| Mozilla | Firefox | 2.0.0.18 |
| Mozilla | Firefox | 2.0.0.19 |
| Mozilla | Firefox | 2.0.0.20 |
| Mozilla | Firefox | 3.0 |
| Mozilla | Firefox | 3.0.1 |
| Mozilla | Firefox | 3.0.2 |
| Mozilla | Firefox | 3.0.3 |
| Mozilla | Firefox | 3.0.4 |
| Mozilla | Firefox | 3.0.5 |
Showing 50 of 86 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/34140Vendor Advisory
- http://secunia.com/advisories/34145Vendor Advisory
- http://secunia.com/advisories/34272Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0632Vendor Advisory
- http://secunia.com/advisories/34140Vendor Advisory
- http://secunia.com/advisories/34145Vendor Advisory
- http://secunia.com/advisories/34272Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0632Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0777?
How severe is CVE-2009-0777?
How do I fix CVE-2009-0777?
Are you affected by CVE-2009-0777?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
