9.3
CVSSv2

CVE-2009-3376

Published: 29/10/2009 Updated: 30/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Mozilla Firefox prior to 3.0.15 and 3.5.x prior to 3.5.4, and SeaMonkey prior to 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote malicious users to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 3.0.10

mozilla firefox 3.0.11

mozilla firefox 3.0.12

mozilla firefox 3.0.7

mozilla firefox 3.0.8

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0.6

mozilla seamonkey 1.0

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.3

mozilla seamonkey 1.1.5

mozilla seamonkey 1.1.8

mozilla seamonkey 1.5.0.9

mozilla firefox 3.0.1

mozilla firefox 3.0.3

mozilla firefox 3.0.2

mozilla firefox 3.5.3

mozilla seamonkey 1.0.8

mozilla seamonkey 1.0.3

mozilla seamonkey 1.0.2

mozilla seamonkey 1.0.9

mozilla seamonkey 1.1.15

mozilla seamonkey 1.1.4

mozilla seamonkey 1.1.6

mozilla seamonkey 1.1.9

mozilla seamonkey 1.5.0.8

mozilla firefox 3.0.13

mozilla firefox 3.0.6

mozilla firefox 3.0.9

mozilla firefox 3.0

mozilla seamonkey 1.0.1

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.10

mozilla seamonkey 1.1.17

mozilla seamonkey 1.1.2

mozilla seamonkey 1.1.7

mozilla seamonkey 1.1

mozilla seamonkey

mozilla firefox 3.0.5

mozilla firefox 3.0.4

mozilla firefox 3.5.1

mozilla firefox 3.5.2

mozilla seamonkey 1.0.5

mozilla seamonkey 1.0.4

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.13

mozilla seamonkey 1.1.11

Vendor Advisories

Synopsis Moderate: thunderbird security update Type/Severity Security Advisory: Moderate Topic An updated thunderbird package that fixes several security issues is nowavailable for Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common V ...
Synopsis Moderate: thunderbird security update Type/Severity Security Advisory: Moderate Topic An updated thunderbird package that fixes several security issues is nowavailable for Red Hat Enterprise Linux 4The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common V ...
Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-3380 Vladimir Vukicevic, Jesse Ruderman, Martijn Wargers, Daniel Banchero, David Keeler and Boris Zbars ...
Several flaws were discovered in the JavaScript engine of Thunderbird If a user had JavaScript enabled and were tricked into viewing malicious web content, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program (CVE-2009-0689, CVE-2009-2463, CVE-2009-3075) ...
Alin Rad Pop discovered a heap-based buffer overflow in Firefox when it converted strings to floating point numbers If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program (CVE-2009-1563) ...
USN-853-1 fixed vulnerabilities in Firefox and Xulrunner The upstream changes introduced regressions that could lead to crashes when processing certain malformed GIF images, fonts and web pages This update fixes the problem ...
Mozilla Foundation Security Advisory 2009-62 Download filename spoofing with RTL override Announced October 27, 2009 Reporter Jesse Ruderman, Sid Stamm Impact Low Products Firefox, SeaMonkey Fixed in ...