Lucene search

K
mozillaMozilla FoundationMFSA2009-71
HistoryDec 15, 2009 - 12:00 a.m.

GeckoActiveXObject exception messages can be used to enumerate installed COM objects — Mozilla

2009-12-1500:00:00
Mozilla Foundation
www.mozilla.org
22

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

EPSS

0.006

Percentile

77.8%

Security researcher Gregory Fleischer reported that the exception messages generated by Mozilla’s GeckoActiveXObject differ based on whether or not the requested COM object’s ProgID is present in the system registry. A malicious site could use this vulnerability to enumerate a list of COM objects installed on a user’s system and create a profile to track the user across browsing sessions.

Affected configurations

Vulners
Node
mozillafirefoxRange<3.0.16
OR
mozillafirefoxRange<3.5.6
OR
mozillaseamonkeyRange<2.0.1
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

EPSS

0.006

Percentile

77.8%