SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-5913

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for…

MEDIUM 4.9EPSS 1.14%

Does this matter?

Lower severity and a low EPSS score (1.14%). Track it; it rarely justifies an emergency change on its own.

Description

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."

CVSS 2.0
4.9 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
EPSS
1.14% probability · 65th percentile
CISA KEV
Not listed
Affected
mozilla/firefox · mozilla/seamonkey
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.