CVE Vulnerabilities

CVE-2008-5913

Published: Jan 20, 2009 | Modified: Sep 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a temporary footprint and an in-session phishing attack.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 3.5 (including) 3.5 (including)
Firefox Mozilla 3.5.1 (including) 3.5.1 (including)
Firefox Mozilla 3.5.2 (including) 3.5.2 (including)
Firefox Mozilla 3.5.3 (including) 3.5.3 (including)
Firefox Mozilla 3.5.4 (including) 3.5.4 (including)
Firefox Mozilla 3.5.5 (including) 3.5.5 (including)
Firefox Mozilla 3.5.6 (including) 3.5.6 (including)
Firefox Mozilla 3.5.7 (including) 3.5.7 (including)
Firefox Mozilla 3.5.8 (including) 3.5.8 (including)
Firefox Mozilla 3.5.9 (including) 3.5.9 (including)

References