5.8
CVSSv2

CVE-2009-2654

Published: 03/08/2009 Updated: 03/10/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

Mozilla Firefox prior to 3.0.13, and 3.5.x prior to 3.5.2, allows remote malicious users to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.0.1

mozilla firefox 2.0.0.19

mozilla firefox 1.0.1

mozilla firefox 3.0.5

mozilla firefox 1.0.4

mozilla firefox 1.0.7

mozilla firefox 2.0_.4

mozilla firefox 2.0_.5

mozilla firefox 2.0.0.10

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.12

mozilla firefox 2.0

mozilla firefox 0.9.2

mozilla firefox 1.0.5

mozilla firefox 3.0

mozilla firefox 2.0_.1

mozilla firefox 2.0_.10

mozilla firefox 2.0.0.21

mozilla firefox 3.0.7

mozilla firefox 0.7

mozilla firefox 0.7.1

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.5

mozilla firefox 1.5.0.10

mozilla firefox 1.5.3

mozilla firefox 1.5

mozilla firefox 2.0.0.6

mozilla firefox 2.0.0.5

mozilla firefox 3.0.3

mozilla firefox 3.0.4

mozilla firefox 0.1

mozilla firefox 0.8

mozilla firefox 0.9.1

mozilla firefox 1.0

mozilla firefox 2.0.0.20

mozilla firefox 0.9

mozilla firefox 1.0.6

mozilla firefox 2.0_.6

mozilla firefox 2.0_.7

mozilla firefox 2.0.0.11

mozilla firefox 2.0.0.16

mozilla firefox 1.4.1

mozilla firefox 0.4

mozilla firefox 0.5

mozilla firefox 1.5.0.11

mozilla firefox 1.5.0.12

mozilla firefox 1.5.0.8

mozilla firefox 1.5.0.9

mozilla firefox 1.5.8

mozilla firefox 1.5.7

mozilla firefox 2.0.0.3

mozilla firefox 2.0.0.2

mozilla firefox 3.0.12

mozilla firefox 2.0.0.13

mozilla firefox 3.2

mozilla firefox

mozilla firefox 2.0.0.17

mozilla firefox 0.3

mozilla firefox 1.5.0.2

mozilla firefox 1.5.0.3

mozilla firefox 1.5.4

mozilla firefox 1.5.1

mozilla firefox 1.5.2

mozilla firefox 1.8

mozilla firefox 2.0.0.4

mozilla firefox 0.9_rc

mozilla firefox 3.0.11

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.18

mozilla firefox 3.5

mozilla firefox 3.0.9

mozilla firefox 3.0.8

mozilla firefox 0.10

mozilla firefox 0.10.1

mozilla firefox 0.9.3

mozilla firefox 1.0.3

mozilla firefox 1.0.2

mozilla firefox 2.0.0.9

mozilla firefox 1.0.8

mozilla firefox 2.0_.9

mozilla firefox 2.0_8

mozilla firefox 2.0.0.15

mozilla firefox 0.6.1

mozilla firefox 0.6

mozilla firefox 0.2

mozilla firefox 2.0.0.7

mozilla firefox 1.5.0.1

mozilla firefox 1.5.0.6

mozilla firefox 1.5.0.7

mozilla firefox 1.5.6

mozilla firefox 1.5.5

mozilla firefox 2.0.0.1

mozilla firefox 3.0.2

mozilla firefox 3.0.6

mozilla firefox 3.0.10

mozilla firefox 3.1

Vendor Advisories

Juan Pablo Lopez Yacubian discovered that Firefox did not properly display invalid URLs If a user were tricked into accessing a malicious website, an attacker could exploit this to spoof the location bar, such as in a phishing attack Furthermore, if the malicious website had a valid SSL certificate, Firefox would display the spoofed page as trust ...
Juan Pablo Lopez Yacubian discovered that incorrect handling of invalid URLs could be used for spoofing the location bar and the SSL certificate status of a web page Xulrunner is no longer supported for the old stable distribution (etch) For the stable distribution (lenny), this problem has been fixed in version 19013-0lenny1 For the unstable ...
Mozilla Foundation Security Advisory 2009-44 Location bar and SSL indicator spoofing via windowopen() on invalid URL Announced August 3, 2009 Reporter Juan Pablo Lopez Yacubian Impact Moderate Products Firefox Fixed i ...

Exploits

source: wwwsecurityfocuscom/bid/35803/info Mozilla Firefox is affected by a URI-spoofing vulnerability An attacker may leverage this issue by inserting arbitrary content to spoof a URI presented to an unsuspecting user This may lead to a false sense of trust because the victim may be presented with a URI of a seemingly trusted site whi ...