CVE-2009-1836
published 2009-06-12CVE-2009-1836: Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document…
PriorityP427medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.03%
78.9th percentile
Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
Affected
180 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.10 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_ubuntu9.3CRITICAL
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xw48-x32w-4m9r: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-1836 [MEDIUM] CWE-287 GHSA-xw48-x32w-4m9r: Mozilla Firefox before 3
Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2009-06-25·CVSS 5.0
CVE-2009-1303 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Several flaws were discovered in the JavaScript engine of Thunderbird. If a
user had JavaScript enabled and were tricked into viewing malicious web
content, a remote attacker could cause a denial of service or possibly
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2009-1303, CVE-2009-1305, CVE-2009-1392, CVE-2009-1833,
CVE-2009-1838)
Several flaws were discovered in the way Thunderbird processed malformed
URI schemes. If a user were tricked into viewing a malicious website and
had JavaScript and plugins enabled, a remote attacker could execute
arbitrary JavaScript or steal private data. (CVE-2009-1306, CVE-2009-1307,
CVE-2009-1309)
Cefn Hoile discovered Thunderbird did not adequa
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-06-12·CVSS 9.3
CVE-2009-1841 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Several flaws were discovered in the browser and JavaScript engines of
Firefox. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-1392,
CVE-2009-1832, CVE-2009-1833, CVE-2009-1837, CVE-2009-1838)
Pavel Cvrcek discovered that Firefox would sometimes display certain
invalid Unicode characters as whitespace. An attacker could exploit this to
spoof the location bar, such as in a phishing attack. (CVE-2009-1834)
Gregory Fleischer, Adam Barth and Collin Jackson discovered that Firefox
would allow access to local files from resources loaded via the
Red Hat
Firefox SSL tampering via non-200 responses to proxy CONNECT requests
vendor_redhat·2009-06-11·CVSS 6.8
CVE-2009-1836 [MEDIUM] Firefox SSL tampering via non-200 responses to proxy CONNECT requests
Firefox SSL tampering via non-200 responses to proxy CONNECT requests
Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
No detection rules found.
http://osvdb.org/55160http://research.microsoft.com/apps/pubs/default.aspx?id=79323http://research.microsoft.com/pubs/79323/pbp-final-with-update.pdfhttp://secunia.com/advisories/35331http://secunia.com/advisories/35415http://secunia.com/advisories/35431http://secunia.com/advisories/35439http://secunia.com/advisories/35440http://secunia.com/advisories/35468http://secunia.com/advisories/35536http://secunia.com/advisories/35561http://secunia.com/advisories/35602http://secunia.com/advisories/35882http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1http://www.debian.org/security/2009/dsa-1820http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:141http://www.mozilla.org/security/announce/2009/mfsa2009-27.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1126.htmlhttp://www.securityfocus.com/bid/35326http://www.securityfocus.com/bid/35380http://www.securitytracker.com/id?1022396http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.454275http://www.ubuntu.com/usn/usn-782-1http://www.vupen.com/english/advisories/2009/1572https://bugzilla.mozilla.org/show_bug.cgi?id=479880https://bugzilla.redhat.com/show_bug.cgi?id=503578https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11764https://rhn.redhat.com/errata/RHSA-2009-1095.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.htmlhttp://osvdb.org/55160http://research.microsoft.com/apps/pubs/default.aspx?id=79323http://research.microsoft.com/pubs/79323/pbp-final-with-update.pdfhttp://secunia.com/advisories/35331http://secunia.com/advisories/35415http://secunia.com/advisories/35431http://secunia.com/advisories/35439http://secunia.com/advisories/35440http://secunia.com/advisories/35468http://secunia.com/advisories/35536http://secunia.com/advisories/35561http://secunia.com/advisories/35602http://secunia.com/advisories/35882http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.425408http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1http://www.debian.org/security/2009/dsa-1820http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:141http://www.mozilla.org/security/announce/2009/mfsa2009-27.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1126.htmlhttp://www.securityfocus.com/bid/35326http://www.securityfocus.com/bid/35380http://www.securitytracker.com/id?1022396http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.454275http://www.ubuntu.com/usn/usn-782-1http://www.vupen.com/english/advisories/2009/1572https://bugzilla.mozilla.org/show_bug.cgi?id=479880https://bugzilla.redhat.com/show_bug.cgi?id=503578https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11764https://rhn.redhat.com/errata/RHSA-2009-1095.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.html
2009-06-12
Published