CVE Vulnerabilities

CVE-2008-0591

Published: Feb 09, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by using a timer to change the window focus, aka the dialog refocus bug or ffclick2.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*2.0.0.11 (including)
ThunderbirdMozilla*2.0.0.11 (including)
Red Hat Enterprise Linux 2.1RedHatseamonkey-0:1.0.9-0.9.el2*
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.9.el3*
Red Hat Enterprise Linux 4RedHatfirefox-0:1.5.0.12-0.10.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-9.el4*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.12-8.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:1.5.0.12-9.el5*
Red Hat Enterprise Linux 5RedHatthunderbird-0:1.5.0.12-8.el5*
FirefoxUbuntudapper*
FirefoxUbuntuedgy*
FirefoxUbuntufeisty*
FirefoxUbuntugutsy*
FirefoxUbuntuhardy*
FirefoxUbuntuupstream*
IceapeUbuntugutsy*
Mozilla-thunderbirdUbuntudapper*
Mozilla-thunderbirdUbuntuedgy*
Mozilla-thunderbirdUbuntufeisty*
Mozilla-thunderbirdUbuntuupstream*
SeamonkeyUbuntudevel*
SeamonkeyUbuntuhardy*
SeamonkeyUbuntuintrepid*
ThunderbirdUbuntudevel*
ThunderbirdUbuntugutsy*
ThunderbirdUbuntuhardy*
ThunderbirdUbuntuintrepid*
ThunderbirdUbuntuupstream*
XulrunnerUbuntudevel*
XulrunnerUbuntuedgy*
XulrunnerUbuntufeisty*
XulrunnerUbuntugutsy*
XulrunnerUbuntuhardy*
XulrunnerUbuntuintrepid*
XulrunnerUbuntuupstream*

References