CVE Vulnerabilities

CVE-2009-0652

Published: Feb 20, 2009 | Modified: Oct 03, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 3.0.6 (including)
Firefox Mozilla 1.0 (including) 1.0 (including)
Firefox Mozilla 1.0.1 (including) 1.0.1 (including)
Firefox Mozilla 1.0.2 (including) 1.0.2 (including)
Firefox Mozilla 1.0.3 (including) 1.0.3 (including)
Firefox Mozilla 1.0.4 (including) 1.0.4 (including)
Firefox Mozilla 1.0.5 (including) 1.0.5 (including)
Firefox Mozilla 1.0.6 (including) 1.0.6 (including)
Firefox Mozilla 1.0.7 (including) 1.0.7 (including)
Firefox Mozilla 1.0.8 (including) 1.0.8 (including)
Firefox Mozilla 1.5 (including) 1.5 (including)
Firefox Mozilla 1.5.0.1 (including) 1.5.0.1 (including)
Firefox Mozilla 1.5.0.2 (including) 1.5.0.2 (including)
Firefox Mozilla 1.5.0.3 (including) 1.5.0.3 (including)
Firefox Mozilla 1.5.0.4 (including) 1.5.0.4 (including)
Firefox Mozilla 1.5.0.5 (including) 1.5.0.5 (including)
Firefox Mozilla 1.5.0.6 (including) 1.5.0.6 (including)
Firefox Mozilla 1.5.0.7 (including) 1.5.0.7 (including)
Firefox Mozilla 1.5.0.8 (including) 1.5.0.8 (including)
Firefox Mozilla 1.5.0.9 (including) 1.5.0.9 (including)
Firefox Mozilla 1.5.0.10 (including) 1.5.0.10 (including)
Firefox Mozilla 1.5.0.11 (including) 1.5.0.11 (including)
Firefox Mozilla 1.5.0.12 (including) 1.5.0.12 (including)
Firefox Mozilla 2.0 (including) 2.0 (including)
Firefox Mozilla 2.0.0.1 (including) 2.0.0.1 (including)
Firefox Mozilla 2.0.0.2 (including) 2.0.0.2 (including)
Firefox Mozilla 2.0.0.3 (including) 2.0.0.3 (including)
Firefox Mozilla 2.0.0.4 (including) 2.0.0.4 (including)
Firefox Mozilla 2.0.0.5 (including) 2.0.0.5 (including)
Firefox Mozilla 2.0.0.6 (including) 2.0.0.6 (including)
Firefox Mozilla 2.0.0.7 (including) 2.0.0.7 (including)
Firefox Mozilla 2.0.0.8 (including) 2.0.0.8 (including)
Firefox Mozilla 2.0.0.9 (including) 2.0.0.9 (including)
Firefox Mozilla 2.0.0.10 (including) 2.0.0.10 (including)
Firefox Mozilla 2.0.0.11 (including) 2.0.0.11 (including)
Firefox Mozilla 2.0.0.12 (including) 2.0.0.12 (including)
Firefox Mozilla 2.0.0.13 (including) 2.0.0.13 (including)
Firefox Mozilla 2.0.0.14 (including) 2.0.0.14 (including)
Firefox Mozilla 2.0.0.15 (including) 2.0.0.15 (including)
Firefox Mozilla 2.0.0.16 (including) 2.0.0.16 (including)
Firefox Mozilla 2.0.0.17 (including) 2.0.0.17 (including)
Firefox Mozilla 2.0.0.18 (including) 2.0.0.18 (including)
Firefox Mozilla 2.0.0.19 (including) 2.0.0.19 (including)
Firefox Mozilla 2.0.0.20 (including) 2.0.0.20 (including)
Firefox Mozilla 3.0 (including) 3.0 (including)
Firefox Mozilla 3.0.1 (including) 3.0.1 (including)
Firefox Mozilla 3.0.2 (including) 3.0.2 (including)
Firefox Mozilla 3.0.3 (including) 3.0.3 (including)
Firefox Mozilla 3.0.4 (including) 3.0.4 (including)
Firefox Mozilla 3.0.5 (including) 3.0.5 (including)
Seamonkey Mozilla * 1.1.14 (including)
Seamonkey Mozilla 1.0 (including) 1.0 (including)
Seamonkey Mozilla 1.0.1 (including) 1.0.1 (including)
Seamonkey Mozilla 1.0.2 (including) 1.0.2 (including)
Seamonkey Mozilla 1.0.3 (including) 1.0.3 (including)
Seamonkey Mozilla 1.0.5 (including) 1.0.5 (including)
Seamonkey Mozilla 1.0.6 (including) 1.0.6 (including)
Seamonkey Mozilla 1.0.7 (including) 1.0.7 (including)
Seamonkey Mozilla 1.0.8 (including) 1.0.8 (including)
Seamonkey Mozilla 1.0.9 (including) 1.0.9 (including)
Seamonkey Mozilla 1.1 (including) 1.1 (including)
Seamonkey Mozilla 1.1-alpha (including) 1.1-alpha (including)
Seamonkey Mozilla 1.1-beta (including) 1.1-beta (including)
Seamonkey Mozilla 1.1.1 (including) 1.1.1 (including)
Seamonkey Mozilla 1.1.2 (including) 1.1.2 (including)
Seamonkey Mozilla 1.1.3 (including) 1.1.3 (including)
Seamonkey Mozilla 1.1.4 (including) 1.1.4 (including)
Seamonkey Mozilla 1.1.5 (including) 1.1.5 (including)
Seamonkey Mozilla 1.1.6 (including) 1.1.6 (including)
Seamonkey Mozilla 1.1.7 (including) 1.1.7 (including)
Seamonkey Mozilla 1.1.8 (including) 1.1.8 (including)
Seamonkey Mozilla 1.1.9 (including) 1.1.9 (including)
Seamonkey Mozilla 1.1.10 (including) 1.1.10 (including)
Seamonkey Mozilla 1.1.11 (including) 1.1.11 (including)
Seamonkey Mozilla 1.1.12 (including) 1.1.12 (including)
Seamonkey Mozilla 1.1.13 (including) 1.1.13 (including)
Thunderbird Mozilla * 2.0.0.20 (including)
Thunderbird Mozilla 2.0.0.0 (including) 2.0.0.0 (including)
Thunderbird Mozilla 2.0.0.4 (including) 2.0.0.4 (including)
Thunderbird Mozilla 2.0.0.5 (including) 2.0.0.5 (including)
Thunderbird Mozilla 2.0.0.6 (including) 2.0.0.6 (including)
Thunderbird Mozilla 2.0.0.9 (including) 2.0.0.9 (including)
Thunderbird Mozilla 2.0.0.12 (including) 2.0.0.12 (including)
Thunderbird Mozilla 2.0.0.14 (including) 2.0.0.14 (including)
Thunderbird Mozilla 2.0.0.16 (including) 2.0.0.16 (including)
Thunderbird Mozilla 2.0.0.17 (including) 2.0.0.17 (including)
Thunderbird Mozilla 2.0.0.18 (including) 2.0.0.18 (including)
Thunderbird Mozilla 2.0.0.19 (including) 2.0.0.19 (including)
Firefox Ubuntu dapper *
Firefox Ubuntu gutsy *
Firefox Ubuntu hardy *
Iceape Ubuntu gutsy *
Seamonkey Ubuntu devel *
Seamonkey Ubuntu hardy *
Seamonkey Ubuntu intrepid *
Seamonkey Ubuntu jaunty *
Seamonkey Ubuntu karmic *
Seamonkey Ubuntu lucid *
Seamonkey Ubuntu maverick *
Seamonkey Ubuntu natty *
Seamonkey Ubuntu oneiric *
Seamonkey Ubuntu upstream *
Xulrunner Ubuntu gutsy *
Xulrunner Ubuntu hardy *
Xulrunner Ubuntu intrepid *
Xulrunner Ubuntu jaunty *
Xulrunner Ubuntu karmic *
Xulrunner-1.9 Ubuntu gutsy *
Xulrunner-1.9 Ubuntu hardy *
Xulrunner-1.9 Ubuntu intrepid *
Xulrunner-1.9 Ubuntu jaunty *
Xulrunner-1.9.1 Ubuntu jaunty *
Xulrunner-1.9.1 Ubuntu karmic *
Red Hat Enterprise Linux 2.1 RedHat seamonkey-0:1.0.9-0.33.el2 *
Red Hat Enterprise Linux 3 RedHat seamonkey-0:1.0.9-0.37.el3 *
Red Hat Enterprise Linux 4 RedHat firefox-0:3.0.9-1.el4 *
Red Hat Enterprise Linux 4 RedHat seamonkey-0:1.0.9-41.el4 *
Red Hat Enterprise Linux 5 RedHat firefox-0:3.0.9-1.el5 *
Red Hat Enterprise Linux 5 RedHat xulrunner-0:1.9.0.9-1.el5 *

References