CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
AI Score
Confidence
High
EPSS
Percentile
96.8%
Several flaws were discovered in the browser engine. If a user were tricked
into viewing a malicious website, a remote attacker could cause a denial of
service or possibly execute arbitrary code with the privileges of the user
invoking the program. (CVE-2009-1302, CVE-2009-1303, CVE-2009-1304,
CVE-2009-1305)
It was discovered that Firefox displayed certain Unicode characters which
could be visually confused with punctuation in valid web addresses in the
location bar. An attacker could exploit this to spoof the location bar,
such as in a phishing attack. (CVE-2009-0652)
Several flaws were discovered in the way Firefox processed malformed URI
schemes. If a user were tricked into viewing a malicious website, a remote
attacker could execute arbitrary JavaScript or steal private data.
(CVE-2009-1306, CVE-2009-1307, CVE-2009-1309, CVE-2009-1310, CVE-2009-1312)
Cefn Hoile discovered Firefox did not adequately protect against embedded
third-party stylesheets. An attacker could exploit this to perform script
injection attacks using XBL bindings. (CVE-2009-1308)
Paolo Amadini discovered that Firefox would submit POST data when reloading
an inner frame of a web page. If a user were tricked into viewing a
malicious website, a remote attacker could steal private data.
(CVE-2009-1311)
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Ubuntu | 9.04 | noarch | firefox-3.0 | < 3.0.9+nobinonly-0ubuntu0.9.04.1 | UNKNOWN |
Ubuntu | 9.04 | noarch | abrowser | < 3.0-branding-3.0.9+nobinonly-0ubuntu0.9.04.1 | UNKNOWN |
Ubuntu | 9.04 | noarch | firefox | < 3.0-3.0.9+nobinonly-0ubuntu0.9.04.1 | UNKNOWN |
Ubuntu | 9.04 | noarch | firefox | < 3.0-branding-3.0.9+nobinonly-0ubuntu0.9.04.1 | UNKNOWN |
Ubuntu | 9.04 | noarch | firefox | < 3.0-dev-3.0.9+nobinonly-0ubuntu0.9.04.1 | UNKNOWN |
Ubuntu | 9.04 | noarch | firefox | < 3.0-gnome-support-3.0.9+nobinonly-0ubuntu0.9.04.1 | UNKNOWN |
Ubuntu | 9.04 | noarch | abrowser | < 3.0.9+nobinonly-0ubuntu0.9.04.1 | UNKNOWN |
Ubuntu | 9.04 | noarch | xulrunner-1.9 | < 1.9.0.9+nobinonly-0ubuntu0.9.04.1 | UNKNOWN |
Ubuntu | 9.04 | noarch | xulrunner-1.9 | < dev-1.9.0.9+nobinonly-0ubuntu0.9.04.1 | UNKNOWN |
Ubuntu | 9.04 | noarch | xulrunner-1.9 | < gnome-support-1.9.0.9+nobinonly-0ubuntu0.9.04.1 | UNKNOWN |
ubuntu.com/security/CVE-2009-0652
ubuntu.com/security/CVE-2009-1302
ubuntu.com/security/CVE-2009-1303
ubuntu.com/security/CVE-2009-1304
ubuntu.com/security/CVE-2009-1305
ubuntu.com/security/CVE-2009-1306
ubuntu.com/security/CVE-2009-1307
ubuntu.com/security/CVE-2009-1308
ubuntu.com/security/CVE-2009-1309
ubuntu.com/security/CVE-2009-1310
ubuntu.com/security/CVE-2009-1311
ubuntu.com/security/CVE-2009-1312