CVE Vulnerabilities

CVE-2009-0652

Published: Feb 20, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*3.0.6 (including)
FirefoxMozilla1.0 (including)1.0 (including)
FirefoxMozilla1.0.1 (including)1.0.1 (including)
FirefoxMozilla1.0.2 (including)1.0.2 (including)
FirefoxMozilla1.0.3 (including)1.0.3 (including)
FirefoxMozilla1.0.4 (including)1.0.4 (including)
FirefoxMozilla1.0.5 (including)1.0.5 (including)
FirefoxMozilla1.0.6 (including)1.0.6 (including)
FirefoxMozilla1.0.7 (including)1.0.7 (including)
FirefoxMozilla1.0.8 (including)1.0.8 (including)
FirefoxMozilla1.5 (including)1.5 (including)
FirefoxMozilla1.5.0.1 (including)1.5.0.1 (including)
FirefoxMozilla1.5.0.2 (including)1.5.0.2 (including)
FirefoxMozilla1.5.0.3 (including)1.5.0.3 (including)
FirefoxMozilla1.5.0.4 (including)1.5.0.4 (including)
FirefoxMozilla1.5.0.5 (including)1.5.0.5 (including)
FirefoxMozilla1.5.0.6 (including)1.5.0.6 (including)
FirefoxMozilla1.5.0.7 (including)1.5.0.7 (including)
FirefoxMozilla1.5.0.8 (including)1.5.0.8 (including)
FirefoxMozilla1.5.0.9 (including)1.5.0.9 (including)
FirefoxMozilla1.5.0.10 (including)1.5.0.10 (including)
FirefoxMozilla1.5.0.11 (including)1.5.0.11 (including)
FirefoxMozilla1.5.0.12 (including)1.5.0.12 (including)
FirefoxMozilla2.0 (including)2.0 (including)
FirefoxMozilla2.0.0.1 (including)2.0.0.1 (including)
FirefoxMozilla2.0.0.2 (including)2.0.0.2 (including)
FirefoxMozilla2.0.0.3 (including)2.0.0.3 (including)
FirefoxMozilla2.0.0.4 (including)2.0.0.4 (including)
FirefoxMozilla2.0.0.5 (including)2.0.0.5 (including)
FirefoxMozilla2.0.0.6 (including)2.0.0.6 (including)
FirefoxMozilla2.0.0.7 (including)2.0.0.7 (including)
FirefoxMozilla2.0.0.8 (including)2.0.0.8 (including)
FirefoxMozilla2.0.0.9 (including)2.0.0.9 (including)
FirefoxMozilla2.0.0.10 (including)2.0.0.10 (including)
FirefoxMozilla2.0.0.11 (including)2.0.0.11 (including)
FirefoxMozilla2.0.0.12 (including)2.0.0.12 (including)
FirefoxMozilla2.0.0.13 (including)2.0.0.13 (including)
FirefoxMozilla2.0.0.14 (including)2.0.0.14 (including)
FirefoxMozilla2.0.0.15 (including)2.0.0.15 (including)
FirefoxMozilla2.0.0.16 (including)2.0.0.16 (including)
FirefoxMozilla2.0.0.17 (including)2.0.0.17 (including)
FirefoxMozilla2.0.0.18 (including)2.0.0.18 (including)
FirefoxMozilla2.0.0.19 (including)2.0.0.19 (including)
FirefoxMozilla2.0.0.20 (including)2.0.0.20 (including)
FirefoxMozilla3.0 (including)3.0 (including)
FirefoxMozilla3.0.1 (including)3.0.1 (including)
FirefoxMozilla3.0.2 (including)3.0.2 (including)
FirefoxMozilla3.0.3 (including)3.0.3 (including)
FirefoxMozilla3.0.4 (including)3.0.4 (including)
FirefoxMozilla3.0.5 (including)3.0.5 (including)
SeamonkeyMozilla*1.1.14 (including)
SeamonkeyMozilla1.0 (including)1.0 (including)
SeamonkeyMozilla1.0.1 (including)1.0.1 (including)
SeamonkeyMozilla1.0.2 (including)1.0.2 (including)
SeamonkeyMozilla1.0.3 (including)1.0.3 (including)
SeamonkeyMozilla1.0.5 (including)1.0.5 (including)
SeamonkeyMozilla1.0.6 (including)1.0.6 (including)
SeamonkeyMozilla1.0.7 (including)1.0.7 (including)
SeamonkeyMozilla1.0.8 (including)1.0.8 (including)
SeamonkeyMozilla1.0.9 (including)1.0.9 (including)
SeamonkeyMozilla1.1 (including)1.1 (including)
SeamonkeyMozilla1.1-alpha (including)1.1-alpha (including)
SeamonkeyMozilla1.1-beta (including)1.1-beta (including)
SeamonkeyMozilla1.1.1 (including)1.1.1 (including)
SeamonkeyMozilla1.1.2 (including)1.1.2 (including)
SeamonkeyMozilla1.1.3 (including)1.1.3 (including)
SeamonkeyMozilla1.1.4 (including)1.1.4 (including)
SeamonkeyMozilla1.1.5 (including)1.1.5 (including)
SeamonkeyMozilla1.1.6 (including)1.1.6 (including)
SeamonkeyMozilla1.1.7 (including)1.1.7 (including)
SeamonkeyMozilla1.1.8 (including)1.1.8 (including)
SeamonkeyMozilla1.1.9 (including)1.1.9 (including)
SeamonkeyMozilla1.1.10 (including)1.1.10 (including)
SeamonkeyMozilla1.1.11 (including)1.1.11 (including)
SeamonkeyMozilla1.1.12 (including)1.1.12 (including)
SeamonkeyMozilla1.1.13 (including)1.1.13 (including)
ThunderbirdMozilla*2.0.0.20 (including)
ThunderbirdMozilla2.0.0.0 (including)2.0.0.0 (including)
ThunderbirdMozilla2.0.0.4 (including)2.0.0.4 (including)
ThunderbirdMozilla2.0.0.5 (including)2.0.0.5 (including)
ThunderbirdMozilla2.0.0.6 (including)2.0.0.6 (including)
ThunderbirdMozilla2.0.0.9 (including)2.0.0.9 (including)
ThunderbirdMozilla2.0.0.12 (including)2.0.0.12 (including)
ThunderbirdMozilla2.0.0.14 (including)2.0.0.14 (including)
ThunderbirdMozilla2.0.0.16 (including)2.0.0.16 (including)
ThunderbirdMozilla2.0.0.17 (including)2.0.0.17 (including)
ThunderbirdMozilla2.0.0.18 (including)2.0.0.18 (including)
ThunderbirdMozilla2.0.0.19 (including)2.0.0.19 (including)
Red Hat Enterprise Linux 2.1RedHatseamonkey-0:1.0.9-0.33.el2*
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.37.el3*
Red Hat Enterprise Linux 4RedHatfirefox-0:3.0.9-1.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-41.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.0.9-1.el5*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.0.9-1.el5*
FirefoxUbuntudapper*
FirefoxUbuntugutsy*
FirefoxUbuntuhardy*
IceapeUbuntugutsy*
SeamonkeyUbuntudevel*
SeamonkeyUbuntuhardy*
SeamonkeyUbuntuintrepid*
SeamonkeyUbuntujaunty*
SeamonkeyUbuntukarmic*
SeamonkeyUbuntulucid*
SeamonkeyUbuntumaverick*
SeamonkeyUbuntunatty*
SeamonkeyUbuntuoneiric*
SeamonkeyUbuntuupstream*
XulrunnerUbuntugutsy*
XulrunnerUbuntuhardy*
XulrunnerUbuntuintrepid*
XulrunnerUbuntujaunty*
XulrunnerUbuntukarmic*
Xulrunner-1.9Ubuntugutsy*
Xulrunner-1.9Ubuntuhardy*
Xulrunner-1.9Ubuntuintrepid*
Xulrunner-1.9Ubuntujaunty*
Xulrunner-1.9.1Ubuntujaunty*
Xulrunner-1.9.1Ubuntukarmic*

References