CVE-2009-3078
published 2009-09-10CVE-2009-3078: Visual truncation vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to trigger a vertical scroll and spoof URLs…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
2.25%
81.1th percentile
Visual truncation vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to trigger a vertical scroll and spoof URLs via unspecified Unicode characters with a tall line-height property.
Affected
96 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.13 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_ubuntu10.0CRITICAL
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q948-rp96-c8w7: Visual truncation vulnerability in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-3078 [MEDIUM] CWE-20 GHSA-q948-rp96-c8w7: Visual truncation vulnerability in Mozilla Firefox before 3
Visual truncation vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to trigger a vertical scroll and spoof URLs via unspecified Unicode characters with a tall line-height property.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-09-10·CVSS 10.0
CVE-2009-3070 [CRITICAL] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Several flaws were discovered in the Firefox browser and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-3070,
CVE-2009-3071, CVE-2009-3072, CVE-2009-3074, CVE-2009-3075)
Jesse Ruderman and Dan Kaminsky discovered that Firefox did not adequately
inform users when security modules were added or removed via PKCS11. If
a user visited a malicious website, an attacker could exploit this to
trick the user into installing a malicious PKCS11 module. (CVE-2009-3076)
It was discovered that Firefox did not properly manage memory wh
Red Hat
Firefox 3.5.3 3.0.14 Location bar spoofing via tall line-height Unicode characters
vendor_redhat·2009-09-09·CVSS 5.0
CVE-2009-3078 [MEDIUM] Firefox 3.5.3 3.0.14 Location bar spoofing via tall line-height Unicode characters
Firefox 3.5.3 3.0.14 Location bar spoofing via tall line-height Unicode characters
Visual truncation vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to trigger a vertical scroll and spoof URLs via unspecified Unicode characters with a tall line-height property.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/36670http://secunia.com/advisories/36671http://secunia.com/advisories/36692http://secunia.com/advisories/37098http://www.debian.org/security/2009/dsa-1885http://www.mozilla.org/security/announce/2009/mfsa2009-50.htmlhttp://www.novell.com/linux/security/advisories/2009_48_firefox.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1430.htmlhttp://www.securityfocus.com/bid/36343http://www.securitytracker.com/id?1022875https://bugzilla.mozilla.org/show_bug.cgi?id=453827https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10871https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5418http://secunia.com/advisories/36670http://secunia.com/advisories/36671http://secunia.com/advisories/36692http://secunia.com/advisories/37098http://www.debian.org/security/2009/dsa-1885http://www.mozilla.org/security/announce/2009/mfsa2009-50.htmlhttp://www.novell.com/linux/security/advisories/2009_48_firefox.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1430.htmlhttp://www.securityfocus.com/bid/36343http://www.securitytracker.com/id?1022875https://bugzilla.mozilla.org/show_bug.cgi?id=453827https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10871https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5418
2009-09-10
Published