Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-0358
HistoryFeb 04, 2009 - 12:00 a.m.

CVE-2009-0358

2009-02-0400:00:00
ubuntu.com
ubuntu.com
13

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

10.1%

Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1)
no-store and (2) no-cache Cache-Control directives, which allows local
users to obtain sensitive information by using the (a) back button or (b)
history list of the victim’s browser, as demonstrated by reading the
response page of an https POST request.

OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchfirefox-3.0< 3.0.6+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu8.10noarchfirefox-3.0< 3.0.6+nobinonly-0ubuntu0.8.10.1UNKNOWN
ubuntu8.04noarchxulrunner-1.9< 1.9.0.6+nobinonly-0ubuntu0.8.04.1UNKNOWN
ubuntu8.10noarchxulrunner-1.9< 1.9.0.6+nobinonly-0ubuntu0.8.10.1UNKNOWN

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

10.1%