SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-1834

Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 allows remote attackers to spoof the location bar via an IDN with invalid Unicode characters that are displayed as…

MEDIUM 4.3EPSS 3.23%

Does this matter?

Lower severity and a low EPSS score (3.23%). Track it; it rarely justifies an emergency change on its own.

Description

Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 allows remote attackers to spoof the location bar via an IDN with invalid Unicode characters that are displayed as whitespace, as demonstrated by the \u115A through \u115E characters.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
3.23% probability · 88th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
mozilla/firefox · mozilla/seamonkey
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.