Lucene search

K
cvelistMitreCVELIST:CVE-2008-5913
HistoryJan 20, 2009 - 4:00 p.m.

CVE-2008-5913

2009-01-2016:00:00
mitre
www.cve.org
7

AI Score

9.1

Confidence

High

EPSS

0.003

Percentile

66.0%

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a β€œtemporary footprint” and an β€œin-session phishing attack.”

References