CVE-2008-5913
published 2009-01-20CVE-2008-5913: The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a…
PriorityP416medium4.9CVSS 2.0
AVNACMAuSCPIPAN
EPSS
1.14%
63.0th percentile
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."
Affected
106 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 5.0.2 | — |
| apple | safari | <= 4.1.2 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
osv4.9MEDIUM
vendor_ubuntu10.0CRITICAL
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and Xulrunner vulnerability
vendor_ubuntu·2010-07-26·CVSS 10.0
CVE-2010-2755 [CRITICAL] Firefox and Xulrunner vulnerability
Title: Firefox and Xulrunner vulnerability
Summary: Firefox could be made to run programs as your login if it opened a
specially crafted file or website.
USN-957-1 fixed vulnerabilities in Firefox and Xulrunner. Daniel Holbert
discovered that the fix for CVE-2010-1214 introduced a regression which did
not properly initialize a plugin pointer. If a user were tricked into
viewing a malicious site, a remote attacker could use this to crash the
browser or run arbitrary code as the user invoking the program.
(CVE-2010-2755)
This update fixes the problem.
Original advisory details:
If was discovered that Firefox could be made to access freed memory. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2010-07-23·CVSS 9.8
CVE-2008-5913 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox could be made to run programs as your login if it opened a
specially crafted file or website.
USN-930-1 fixed vulnerabilities in Firefox and Xulrunner. This update
provides the corresponding updates for Ubuntu 9.04 and 9.10, along with
additional updates affecting Firefox 3.6.6.
Several flaws were discovered in the browser engine of Firefox. If a user
were tricked into viewing a malicious site, a remote attacker could use
this to crash the browser or possibly run arbitrary code as the user
invoking the program. (CVE-2010-1208, CVE-2010-1209, CVE-2010-1211,
CVE-2010-1212)
An integer overflow was discovered in how Firefox processed plugin
parameters. An attacker could exploit this to crash the browser or possibly
run arbitrary
Ubuntu
ant, apturl, Epiphany, gluezilla, gnome-python-extras, liferea, mozvoikko, OpenJDK, packagekit, ubufox, webfav, yelp update
vendor_ubuntu·2010-07-23·CVSS 10.0
[CRITICAL] ant, apturl, Epiphany, gluezilla, gnome-python-extras, liferea, mozvoikko, OpenJDK, packagekit, ubufox, webfav, yelp update
Title: ant, apturl, Epiphany, gluezilla, gnome-python-extras, liferea, mozvoikko, OpenJDK, packagekit, ubufox, webfav, yelp update
Summary: This update is for use with the new Xulrunner provided in USN-930-4.
USN-930-4 fixed vulnerabilities in Firefox and Xulrunner on Ubuntu 9.04 and
9.10. This update provides updated packages for use with Firefox 3.6 and
Xulrunner 1.9.2.
Original advisory details:
If was discovered that Firefox could be made to access freed memory. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS. (CVE-2010-1121)
Several flaws were discovered in the browser engine of Firefox. If a
user
Ubuntu
Firefox regression
vendor_ubuntu·2010-06-30·CVSS 10.0
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: This update fixes a problem with Firefox not installing alongside the old
Firefox 2 package.
USN-930-1 fixed vulnerabilities in Firefox. Due to a software packaging
problem, the Firefox 3.6 update could not be installed when the firefox-2
package was also installed. This update fixes the problem and updates
apturl for the change.
Original advisory details:
If was discovered that Firefox could be made to access freed memory. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS. (CVE-2010-1121)
Several flaws were discovered in the browser engine of Firefox. If a
user were tr
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2010-06-29·CVSS 10.0
CVE-2010-1121 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox could be made to run programs as your login if it opened a
specially crafted file or website.
If was discovered that Firefox could be made to access freed memory. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS. (CVE-2010-1121)
Several flaws were discovered in the browser engine of Firefox. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,
CVE-2010-1202, CVE-2010-1203)
A
Ubuntu
apturl, Epiphany, gecko-sharp, gnome-python-extras, liferea, rhythmbox, totem, ubufox, yelp update
vendor_ubuntu·2010-06-29·CVSS 10.0
[CRITICAL] apturl, Epiphany, gecko-sharp, gnome-python-extras, liferea, rhythmbox, totem, ubufox, yelp update
Title: apturl, Epiphany, gecko-sharp, gnome-python-extras, liferea, rhythmbox, totem, ubufox, yelp update
Summary: This update is for use with the new Xulrunner provided in USN-930-1.
USN-930-1 fixed vulnerabilities in Firefox and Xulrunner. This update
provides updated packages for use with Firefox 3.6 and Xulrunner 1.9.2 on
Ubuntu 8.04 LTS.
Original advisory details:
If was discovered that Firefox could be made to access freed memory. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS. (CVE-2010-1121)
Several flaws were discovered in the browser engine of Firefox. If a
user were tricked into viewing a m
Red Hat
mozilla: in-session phishing attack
vendor_redhat·2009-01-13·CVSS 4.9
CVE-2008-5913 [MEDIUM] mozilla: in-session phishing attack
mozilla: in-session phishing attack
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."
Package: seamonkey (Red Hat Enterprise Linux 4) - Will not fix
GHSA
GHSA-7mj9-f8rr-cqvj: The Math
ghsa_unreviewed·2022-05-17
CVE-2008-5913 [MEDIUM] GHSA-7mj9-f8rr-cqvj: The Math
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."
GHSA
GHSA-h84m-77j2-99hq: The JavaScript implementation in WebKit in Apple Safari before 5
ghsa_unreviewed·2022-05-17·CVSS 4.9
CVE-2010-3804 [MEDIUM] GHSA-h84m-77j2-99hq: The JavaScript implementation in WebKit in Apple Safari before 5
The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, uses a weak algorithm for generating values of random numbers, which makes it easier for remote attackers to track a user by predicting a value, a related issue to CVE-2008-5913 and CVE-2010-3171.
GHSA
GHSA-83cp-2h62-q83c: The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3
ghsa_unreviewed·2022-05-17·CVSS 4.9
CVE-2010-3400 [MEDIUM] GHSA-83cp-2h62-q83c: The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3
The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses the current time for seeding of a random number generator, which makes it easier for remote attackers to guess the seed value via a brute-force attack, a different vulnerability than CVE-2008-5913.
GHSA
GHSA-v4fq-jrv5-w6jf: The Math
ghsa_unreviewed·2022-05-17·CVSS 4.9
CVE-2010-3171 [MEDIUM] GHSA-v4fq-jrv5-w6jf: The Math
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random number generator that is seeded only once per document object, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack." NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-5913.
OSV
CVE-2010-3804: The JavaScript implementation in WebKit in Apple Safari before 5
osv·2010-11-22·CVSS 4.9
CVE-2010-3804 [MEDIUM] CVE-2010-3804: The JavaScript implementation in WebKit in Apple Safari before 5
The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, uses a weak algorithm for generating values of random numbers, which makes it easier for remote attackers to track a user by predicting a value, a related issue to CVE-2008-5913 and CVE-2010-3171.
No detection rules found.
No public exploits indexed.
http://arstechnica.com/news.ars/post/20090113-new-method-of-phishmongering-could-fool-experienced-users.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/043369.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/043405.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.htmlhttp://secunia.com/advisories/40326http://secunia.com/advisories/40401http://secunia.com/advisories/40481http://support.avaya.com/css/P8/documents/100091069http://ubuntu.com/usn/usn-930-1http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=212900161http://www.infoworld.com/article/09/01/13/Browser_bug_could_allow_phishing_without_email_1.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:125http://www.mozilla.org/security/announce/2010/mfsa2010-33.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0500.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0501.htmlhttp://www.securityfocus.com/bid/33276http://www.trusteer.com/files/In-session-phishing-advisory-2.pdfhttp://www.ubuntu.com/usn/usn-930-2http://www.vupen.com/english/advisories/2010/1551http://www.vupen.com/english/advisories/2010/1557http://www.vupen.com/english/advisories/2010/1592http://www.vupen.com/english/advisories/2010/1640http://www.vupen.com/english/advisories/2010/1773https://bugzilla.mozilla.org/show_bug.cgi?id=475585https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11139http://arstechnica.com/news.ars/post/20090113-new-method-of-phishmongering-could-fool-experienced-users.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/043369.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/043405.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.htmlhttp://secunia.com/advisories/40326http://secunia.com/advisories/40401http://secunia.com/advisories/40481http://support.avaya.com/css/P8/documents/100091069http://ubuntu.com/usn/usn-930-1http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=212900161http://www.infoworld.com/article/09/01/13/Browser_bug_could_allow_phishing_without_email_1.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2010:125http://www.mozilla.org/security/announce/2010/mfsa2010-33.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0500.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0501.htmlhttp://www.securityfocus.com/bid/33276http://www.trusteer.com/files/In-session-phishing-advisory-2.pdfhttp://www.ubuntu.com/usn/usn-930-2http://www.vupen.com/english/advisories/2010/1551http://www.vupen.com/english/advisories/2010/1557http://www.vupen.com/english/advisories/2010/1592http://www.vupen.com/english/advisories/2010/1640http://www.vupen.com/english/advisories/2010/1773https://bugzilla.mozilla.org/show_bug.cgi?id=475585https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11139
2009-01-20
Published