CVE-2009-3987
published 2009-12-17CVE-2009-3987: The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages…
PriorityP430high7.8CVSS 2.0
AVNACLAuNCCINAN
EPSS
1.62%
73.3th percentile
The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects.
Affected
135 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.15 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vwqf-r5hr-488h: The GeckoActiveXObject function in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-02
CVE-2009-3987 [HIGH] CWE-200 GHSA-vwqf-r5hr-488h: The GeckoActiveXObject function in Mozilla Firefox before 3
The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects.
Red Hat
Mozilla GeckoActiveXObject exception messages can be used to enumerate installed COM objects
vendor_redhat·2009-12-15·CVSS 7.8
CVE-2009-3987 [HIGH] Mozilla GeckoActiveXObject exception messages can be used to enumerate installed COM objects
Mozilla GeckoActiveXObject exception messages can be used to enumerate installed COM objects
The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/37699http://secunia.com/advisories/37785http://securitytracker.com/id?1023346http://securitytracker.com/id?1023347http://www.mozilla.org/security/announce/2009/mfsa2009-71.htmlhttp://www.securityfocus.com/bid/37349http://www.securityfocus.com/bid/37360http://www.vupen.com/english/advisories/2009/3547https://bugzilla.mozilla.org/show_bug.cgi?id=503451https://bugzilla.redhat.com/show_bug.cgi?id=546729https://exchange.xforce.ibmcloud.com/vulnerabilities/54798https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7958http://secunia.com/advisories/37699http://secunia.com/advisories/37785http://securitytracker.com/id?1023346http://securitytracker.com/id?1023347http://www.mozilla.org/security/announce/2009/mfsa2009-71.htmlhttp://www.securityfocus.com/bid/37349http://www.securityfocus.com/bid/37360http://www.vupen.com/english/advisories/2009/3547https://bugzilla.mozilla.org/show_bug.cgi?id=503451https://bugzilla.redhat.com/show_bug.cgi?id=546729https://exchange.xforce.ibmcloud.com/vulnerabilities/54798https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7958
2009-12-17
Published