4.9
CVSSv2

CVE-2008-5913

Published: 20/01/2009 Updated: 29/09/2017
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x prior to 3.5.10 and 3.6.x prior to 3.6.4, and SeaMonkey prior to 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote malicious users to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.5.5

mozilla firefox 3.5.6

mozilla firefox 3.5.3

mozilla firefox 3.5.4

mozilla firefox 3.5.1

mozilla firefox 3.5.2

mozilla firefox 3.5.9

mozilla firefox 3.5

mozilla firefox 3.5.7

mozilla firefox 3.5.8

mozilla firefox 3.6.4

mozilla firefox 3.6.2

mozilla firefox 3.6.3

mozilla firefox 3.6

mozilla seamonkey 2.0

mozilla seamonkey 1.0.2

mozilla seamonkey 1.0.3

mozilla seamonkey 1.0

mozilla seamonkey 1.1

mozilla seamonkey 1.1.15

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.7

mozilla seamonkey 1.1.8

mozilla seamonkey 1.1.9

mozilla seamonkey 1.0.1

mozilla seamonkey 1.0.9

mozilla seamonkey 1.1.13

mozilla seamonkey 2.0.2

mozilla seamonkey 2.0.1

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0.8

mozilla seamonkey 1.1.11

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.3

mozilla seamonkey 1.1.4

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.5

mozilla seamonkey 1.1.6

mozilla seamonkey

mozilla seamonkey 2.0.3

mozilla seamonkey 1.0.4

mozilla seamonkey 1.0.5

mozilla seamonkey 1.0.6

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.10

mozilla seamonkey 1.1.17

mozilla seamonkey 1.1.2

Vendor Advisories

Firefox could be made to run programs as your login if it opened a specially crafted file or website ...
This update fixes a problem with Firefox not installing alongside the old Firefox 2 package ...
Firefox could be made to run programs as your login if it opened a specially crafted file or website ...
Firefox could be made to run programs as your login if it opened a specially crafted file or website ...
Mozilla Foundation Security Advisory 2010-33 User tracking across sites using Mathrandom() Announced June 22, 2010 Reporter Amit Klein Impact Low Products Firefox, SeaMonkey Fixed in ...

References

NVD-CWE-Otherhttp://www.infoworld.com/article/09/01/13/Browser_bug_could_allow_phishing_without_email_1.htmlhttp://www.trusteer.com/files/In-session-phishing-advisory-2.pdfhttp://www.securityfocus.com/bid/33276http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=212900161http://arstechnica.com/news.ars/post/20090113-new-method-of-phishmongering-could-fool-experienced-users.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=475585http://www.mozilla.org/security/announce/2010/mfsa2010-33.htmlhttp://www.vupen.com/english/advisories/2010/1557http://www.mandriva.com/security/advisories?name=MDVSA-2010:125http://www.vupen.com/english/advisories/2010/1551http://www.redhat.com/support/errata/RHSA-2010-0500.htmlhttp://secunia.com/advisories/40326http://www.redhat.com/support/errata/RHSA-2010-0501.htmlhttp://support.avaya.com/css/P8/documents/100091069http://secunia.com/advisories/40401http://ubuntu.com/usn/usn-930-1http://www.ubuntu.com/usn/usn-930-2http://www.vupen.com/english/advisories/2010/1640http://lists.opensuse.org/opensuse-security-announce/2010-07/msg00005.htmlhttp://secunia.com/advisories/40481http://www.vupen.com/english/advisories/2010/1773http://lists.fedoraproject.org/pipermail/package-announce/2010-June/043369.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-June/043405.htmlhttp://www.vupen.com/english/advisories/2010/1592https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11139https://nvd.nist.govhttps://usn.ubuntu.com/930-1/