CVE Vulnerabilities

CVE-2009-0652

Published: Feb 20, 2009 | Modified: Oct 03, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.

Affected Software

Name Vendor Start Version End Version
Seamonkey Mozilla 1.1.10 1.1.10
Seamonkey Mozilla 1.0.3 1.0.3
Firefox Mozilla 2.0.0.12 2.0.0.12
Thunderbird Mozilla 2.0.0.4 2.0.0.4
Seamonkey Mozilla 1.1.8 1.1.8
Seamonkey Mozilla 1.0.1 1.0.1
Seamonkey Mozilla 1.1.7 1.1.7
Thunderbird Mozilla 2.0.0.6 2.0.0.6
Seamonkey Mozilla 1.0.6 1.0.6
Firefox Mozilla 1.5.0.6 1.5.0.6
Seamonkey Mozilla 1.0.9 1.0.9
Seamonkey Mozilla * 1.1.14
Seamonkey Mozilla 1.1.3 1.1.3
Firefox Mozilla 2.0.0.2 2.0.0.2
Firefox Mozilla 1.5.0.10 1.5.0.10
Firefox Mozilla 1.5.0.3 1.5.0.3
Seamonkey Mozilla 1.0 1.0
Firefox Mozilla 1.5.0.11 1.5.0.11
Thunderbird Mozilla 2.0.0.18 2.0.0.18
Thunderbird Mozilla 2.0.0.9 2.0.0.9
Seamonkey Mozilla 1.1.5 1.1.5
Seamonkey Mozilla 1.0.7 1.0.7
Firefox Mozilla 1.0.2 1.0.2
Firefox Mozilla 3.0.4 3.0.4
Seamonkey Mozilla 1.1 1.1
Thunderbird Mozilla 2.0.0.16 2.0.0.16
Firefox Mozilla 3.0.5 3.0.5
Firefox Mozilla 1.5 1.5
Firefox Mozilla 1.0.4 1.0.4
Firefox Mozilla 2.0.0.7 2.0.0.7
Firefox Mozilla 1.0.7 1.0.7
Seamonkey Mozilla 1.1.12 1.1.12
Seamonkey Mozilla 1.1 1.1
Firefox Mozilla 2.0.0.9 2.0.0.9
Firefox Mozilla 2.0.0.16 2.0.0.16
Thunderbird Mozilla * 2.0.0.20
Firefox Mozilla 2.0.0.17 2.0.0.17
Seamonkey Mozilla 1.1.2 1.1.2
Firefox Mozilla 2.0.0.15 2.0.0.15
Seamonkey Mozilla 1.0.2 1.0.2
Seamonkey Mozilla 1.0.8 1.0.8
Thunderbird Mozilla 2.0.0.0 2.0.0.0
Seamonkey Mozilla 1.1.11 1.1.11
Firefox Mozilla 1.0 1.0
Firefox Mozilla 3.0.3 3.0.3
Seamonkey Mozilla 1.1 1.1
Seamonkey Mozilla 1.1.1 1.1.1
Firefox Mozilla 1.5.0.7 1.5.0.7
Thunderbird Mozilla 2.0.0.12 2.0.0.12
Firefox Mozilla 2.0 2.0
Firefox Mozilla 1.0.1 1.0.1
Firefox Mozilla 2.0.0.14 2.0.0.14
Seamonkey Mozilla 1.0.5 1.0.5
Thunderbird Mozilla 2.0.0.14 2.0.0.14
Firefox Mozilla 1.5.0.8 1.5.0.8
Firefox Mozilla 2.0.0.3 2.0.0.3
Firefox Mozilla 1.5.0.9 1.5.0.9
Thunderbird Mozilla 2.0.0.17 2.0.0.17
Firefox Mozilla 1.5.0.5 1.5.0.5
Firefox Mozilla 1.5.0.12 1.5.0.12
Firefox Mozilla 2.0.0.6 2.0.0.6
Seamonkey Mozilla 1.1.6 1.1.6
Firefox Mozilla 3.0 3.0
Firefox Mozilla 2.0.0.11 2.0.0.11
Firefox Mozilla 1.5.0.2 1.5.0.2
Firefox Mozilla 1.0.3 1.0.3
Firefox Mozilla 3.0.1 3.0.1
Firefox Mozilla 2.0.0.4 2.0.0.4
Firefox Mozilla 2.0.0.13 2.0.0.13
Firefox Mozilla 2.0.0.18 2.0.0.18
Firefox Mozilla * 3.0.6
Firefox Mozilla 2.0.0.1 2.0.0.1
Firefox Mozilla 3.0.2 3.0.2
Thunderbird Mozilla 2.0.0.5 2.0.0.5
Seamonkey Mozilla 1.1.9 1.1.9
Seamonkey Mozilla 1.1.13 1.1.13
Firefox Mozilla 2.0.0.20 2.0.0.20
Firefox Mozilla 2.0.0.8 2.0.0.8
Firefox Mozilla 2.0.0.19 2.0.0.19
Firefox Mozilla 1.5.0.4 1.5.0.4
Firefox Mozilla 1.5.0.1 1.5.0.1
Firefox Mozilla 1.0.5 1.0.5
Firefox Mozilla 2.0.0.5 2.0.0.5
Firefox Mozilla 2.0.0.10 2.0.0.10
Thunderbird Mozilla 2.0.0.19 2.0.0.19
Firefox Mozilla 1.0.6 1.0.6
Seamonkey Mozilla 1.1.4 1.1.4
Firefox Mozilla 1.0.8 1.0.8

References