7.8
CVSSv2

CVE-2009-3987

Published: 17/12/2009 Updated: 19/09/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

The GeckoActiveXObject function in Mozilla Firefox prior to 3.0.16 and 3.5.x prior to 3.5.6, and SeaMonkey prior to 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote malicious users to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0.6

mozilla seamonkey 1.0

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1.15

mozilla seamonkey 1.1.6

mozilla seamonkey 1.1.9

mozilla seamonkey 1.5.0.10

mozilla seamonkey 2.0

mozilla seamonkey 2.0a1

mozilla seamonkey 2.0a1pre

mozilla firefox 0.6

mozilla firefox 0.1

mozilla firefox 0.7

mozilla firefox 0.9.2

mozilla firefox 1.0.5

mozilla firefox 1.0.4

mozilla firefox 1.5.0.2

mozilla firefox 1.5.0.3

mozilla firefox 1.5.5

mozilla firefox 1.5.3

mozilla firefox 1.5

mozilla firefox 2.0

mozilla firefox 2.0.0.11

mozilla firefox 2.0.0.12

mozilla firefox 2.0.0.19

mozilla firefox 2.0.0.2

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.9

mozilla firefox 2.0_.6

mozilla firefox 3.0.10

mozilla firefox 3.0.11

mozilla firefox 3.0.6

mozilla firefox 3.0.7

mozilla firefox 3.5.1

mozilla seamonkey 1.0.1

mozilla seamonkey 1.1

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.4

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.3

mozilla seamonkey 1.1.5

mozilla seamonkey 1.5.0.8

mozilla seamonkey

mozilla firefox 0.10.1

mozilla firefox 0.2

mozilla firefox 0.10

mozilla firefox 0.7.1

mozilla firefox 1.0

mozilla firefox 1.0.7

mozilla firefox 1.0.6

mozilla firefox 1.5.0.11

mozilla firefox 1.5.0.12

mozilla firefox 1.5.4

mozilla firefox 1.5.1

mozilla firefox 1.8

mozilla firefox 1.5.8

mozilla firefox 2.0.0.13

mozilla firefox 2.0.0.14

mozilla firefox 2.0.0.20

mozilla firefox 2.0.0.21

mozilla firefox 2.0_.7

mozilla firefox 2.0_.9

mozilla firefox 3.0.12

mozilla firefox 3.0.13

mozilla firefox 3.0.14

mozilla firefox 3.0.8

mozilla firefox 3.0.9

mozilla firefox 3.5.5

mozilla seamonkey 1.0.8

mozilla seamonkey 1.0.3

mozilla seamonkey 1.0.2

mozilla seamonkey 1.0.9

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.13

mozilla seamonkey 1.1.11

mozilla seamonkey 1.1.7

mozilla firefox 0.4

mozilla firefox 0.5

mozilla firefox 0.9

mozilla firefox 0.9.3

mozilla firefox 1.0.3

mozilla firefox 1.0.2

mozilla firefox 1.4.1

mozilla firefox 1.5.0.5

mozilla firefox 1.5.6

mozilla firefox 1.5.0.6

mozilla firefox 1.5.0.7

mozilla firefox 2.0.0.10

mozilla firefox 2.0.0.1

mozilla firefox 2.0.0.17

mozilla firefox 2.0.0.18

mozilla firefox 2.0.0.6

mozilla firefox 2.0.0.7

mozilla firefox 2.0_.4

mozilla firefox 2.0_.5

mozilla firefox 3.0

mozilla firefox 3.0.1

mozilla firefox 3.0.4

mozilla firefox 3.0.5

mozilla firefox

mozilla firefox 3.5.2

mozilla firefox 3.5.3

mozilla firefox 3.5.4

mozilla seamonkey 1.0.5

mozilla seamonkey 1.0.4

mozilla seamonkey 1.1.10

mozilla seamonkey 1.0.99

mozilla seamonkey 1.1.17

mozilla seamonkey 1.1.2

mozilla seamonkey 1.1.8

mozilla seamonkey 1.5.0.9

mozilla firefox 0.6.1

mozilla firefox 0.3

mozilla firefox 0.8

mozilla firefox 0.9.1

mozilla firefox 1.0.1

mozilla firefox 1.0.8

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.1

mozilla firefox 1.5.0.10

mozilla firefox 1.5.2

mozilla firefox 1.5.0.8

mozilla firefox 1.5.0.9

mozilla firefox 1.5.7

mozilla firefox 2.0.0.15

mozilla firefox 2.0.0.16

mozilla firefox 2.0.0.3

mozilla firefox 2.0.0.4

mozilla firefox 2.0.0.5

mozilla firefox 2.0_.1

mozilla firefox 2.0_.10

mozilla firefox 2.0_8

mozilla firefox 3.0.2

mozilla firefox 3.0.3

Vendor Advisories

Mozilla Foundation Security Advisory 2009-71 GeckoActiveXObject exception messages can be used to enumerate installed COM objects Announced December 15, 2009 Reporter Gregory Fleischer Impact Low Products Firefox, SeaMonkey ...