CVE-2009-0777
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
05/03/2009
Last modified:
09/04/2025
Description
Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.
Impact
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | 3.0.6 (including) | |
| cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.0.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.5.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:1.5.0.4:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.html
- http://secunia.com/advisories/34140
- http://secunia.com/advisories/34145
- http://secunia.com/advisories/34272
- http://securitytracker.com/alerts/2009/Mar/1021799.html
- http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm
- http://support.avaya.com/japple/css/japple?temp_documentID=366362&temp_productID=154235&temp_releaseID=361845&temp_bucketID=126655&PAGE=Document
- http://www.mandriva.com/security/advisories?name=MDVSA-2009%3A075
- http://www.mozilla.org/security/announce/2009/mfsa2009-11.html
- http://www.redhat.com/support/errata/RHSA-2009-0315.html
- http://www.securityfocus.com/bid/33990
- http://www.vupen.com/english/advisories/2009/0632
- https://bugzilla.mozilla.org/show_bug.cgi?id=452979
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49087
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11222
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6039
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6157
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6229
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7435
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00002.html
- http://secunia.com/advisories/34140
- http://secunia.com/advisories/34145
- http://secunia.com/advisories/34272
- http://securitytracker.com/alerts/2009/Mar/1021799.html
- http://support.avaya.com/elmodocs2/security/ASA-2009-069.htm
- http://support.avaya.com/japple/css/japple?temp_documentID=366362&temp_productID=154235&temp_releaseID=361845&temp_bucketID=126655&PAGE=Document
- http://www.mandriva.com/security/advisories?name=MDVSA-2009%3A075
- http://www.mozilla.org/security/announce/2009/mfsa2009-11.html
- http://www.redhat.com/support/errata/RHSA-2009-0315.html
- http://www.securityfocus.com/bid/33990
- http://www.vupen.com/english/advisories/2009/0632
- https://bugzilla.mozilla.org/show_bug.cgi?id=452979
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49087
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11222
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6039
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6157
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6229
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7435



