CVE-2009-0777
published 2009-03-05CVE-2009-0777: Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar…
PriorityP419medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
1.50%
71.3th percentile
Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.6 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
vendor_redhat7.1HIGH
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
dovecot: Insecure permissions set for certain directories at installation time
vendor_redhat·2009-11-20·CVSS 5.5
CVE-2009-3897 [MEDIUM] CWE-732 dovecot: Insecure permissions set for certain directories at installation time
dovecot: Insecure permissions set for certain directories at installation time
Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
Statement: This issue did not affect the version of dovecot shipped with Red Hat Enterprise Linux 6.
Package: dovecot (Red Hat Enterprise Linux 4) - Not affected
Package: dovecot (Red Hat Enterprise Linux 5) - Will not fix
Package: dovecot (Red Hat Enterprise Linux 6) - Not affected
Red Hat
backintime: makes all files world-readable in snapshot when removing it
vendor_redhat·2009-08-27·CVSS 7.1
CVE-2009-3611 [HIGH] backintime: makes all files world-readable in snapshot when removing it
backintime: makes all files world-readable in snapshot when removing it
common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-03-05·CVSS 6.8
CVE-2009-0773 [MEDIUM] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Glenn Randers-Pehrson discovered that the embedded libpng in Firefox
did not properly initialize pointers. If a user were tricked into
viewing a malicious website with a crafted PNG file, a remote attacker
could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-0040)
Martijn Wargers, Jesse Ruderman, Josh Soref, Gary Kwong, and Timothee
Groleau discovered flaws in the browser engine. If a user were tricked
into viewing a malicious website, a remote attacker could cause a
denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-0771,
CVE-2009-0772, CVE-2009-0773, CV
Red Hat
Firefox URL spoofing with invisible control characters
vendor_redhat·2009-03-04·CVSS 5.8
CVE-2009-0777 [MEDIUM] Firefox URL spoofing with invisible control characters
Firefox URL spoofing with invisible control characters
Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.
GHSA
GHSA-9q9q-525p-x46x: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-0777 [MEDIUM] CWE-20 GHSA-9q9q-525p-x46x: Mozilla Firefox before 3
Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.htmlhttp://secunia.com/advisories/34140http://secunia.com/advisories/34145http://secunia.com/advisories/34272http://securitytracker.com/alerts/2009/Mar/1021799.htmlhttp://support.avaya.com/elmodocs2/security/ASA-2009-069.htmhttp://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.productID=154235&temp.releaseID=361845&temp.bucketID=126655&PAGE=Documenthttp://www.mandriva.com/security/advisories?name=MDVSA-2009:075http://www.mozilla.org/security/announce/2009/mfsa2009-11.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0315.htmlhttp://www.securityfocus.com/bid/33990http://www.vupen.com/english/advisories/2009/0632https://bugzilla.mozilla.org/show_bug.cgi?id=452979https://exchange.xforce.ibmcloud.com/vulnerabilities/49087https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11222https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6039https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6157https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6229https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7435http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.htmlhttp://secunia.com/advisories/34140http://secunia.com/advisories/34145http://secunia.com/advisories/34272http://securitytracker.com/alerts/2009/Mar/1021799.htmlhttp://support.avaya.com/elmodocs2/security/ASA-2009-069.htmhttp://support.avaya.com/japple/css/japple?temp.documentID=366362&temp.productID=154235&temp.releaseID=361845&temp.bucketID=126655&PAGE=Documenthttp://www.mandriva.com/security/advisories?name=MDVSA-2009:075http://www.mozilla.org/security/announce/2009/mfsa2009-11.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0315.htmlhttp://www.securityfocus.com/bid/33990http://www.vupen.com/english/advisories/2009/0632https://bugzilla.mozilla.org/show_bug.cgi?id=452979https://exchange.xforce.ibmcloud.com/vulnerabilities/49087https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11222https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6039https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6157https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6229https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7435
2009-03-05
Published