CVE Database
/

CVE-2008-0591

Back to search

CVE-2008-0591

Published: Feb 8, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by using a timer to change the window focus, aka the "dialog refocus bug" or "ffclick2".

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2008:0104
vendor-advisory
x_refsource_REDHAT
USN-576-1
vendor-advisory
x_refsource_UBUNTU
28939
third-party-advisory
x_refsource_SECUNIA
DSA-1506
vendor-advisory
x_refsource_DEBIAN
FEDORA-2008-2118
vendor-advisory
x_refsource_FEDORA
FEDORA-2008-2060
vendor-advisory
x_refsource_FEDORA
28766
third-party-advisory
x_refsource_SECUNIA
28818
third-party-advisory
x_refsource_SECUNIA
30620
third-party-advisory
x_refsource_SECUNIA
28865
third-party-advisory
x_refsource_SECUNIA
29049
third-party-advisory
x_refsource_SECUNIA
ADV-2008-0453
vdb-entry
x_refsource_VUPEN
RHSA-2008:0103
vendor-advisory
x_refsource_REDHAT
28877
third-party-advisory
x_refsource_SECUNIA
28879
third-party-advisory
x_refsource_SECUNIA
29167
third-party-advisory
x_refsource_SECUNIA
29567
third-party-advisory
x_refsource_SECUNIA
RHSA-2008:0105
vendor-advisory
x_refsource_REDHAT
28958
third-party-advisory
x_refsource_SECUNIA
30327
third-party-advisory
x_refsource_SECUNIA
238492
vendor-advisory
x_refsource_SUNALERT
oval:org.mitre.oval:def:10900
vdb-entry
signature
x_refsource_OVAL
20080229 rPSA-2008-0093-1 thunderbird
mailing-list
x_refsource_BUGTRAQ
DSA-1489
vendor-advisory
x_refsource_DEBIAN
20080212 FLEA-2008-0001-1 firefox
mailing-list
x_refsource_BUGTRAQ
20080209 rPSA-2008-0051-1 firefox
mailing-list
x_refsource_BUGTRAQ
29086
third-party-advisory
x_refsource_SECUNIA
ADV-2008-0454
vdb-entry
x_refsource_VUPEN
28864
third-party-advisory
x_refsource_SECUNIA
DSA-1485
vendor-advisory
x_refsource_DEBIAN
28924
third-party-advisory
x_refsource_SECUNIA
27683
vdb-entry
x_refsource_BID
20070604 Assorted browser vulnerabilities
mailing-list
x_refsource_FULLDISC
ADV-2008-1793
vdb-entry
x_refsource_VUPEN
20070604 Assorted browser vulnerabilities
mailing-list
x_refsource_BUGTRAQ
1019339
vdb-entry
x_refsource_SECTRACK
SUSE-SA:2008:008
vendor-advisory
x_refsource_SUSE
24293
vdb-entry
x_refsource_BID
2781
third-party-advisory
x_refsource_SREASON
FEDORA-2008-1459
vendor-advisory
x_refsource_FEDORA
29164
third-party-advisory
x_refsource_SECUNIA
FEDORA-2008-1535
vendor-advisory
x_refsource_FEDORA
MDVSA-2008:062
vendor-advisory
x_refsource_MANDRIVA
DSA-1484
vendor-advisory
x_refsource_DEBIAN
28808
third-party-advisory
x_refsource_SECUNIA
ADV-2008-0627
vdb-entry
x_refsource_VUPEN
GLSA-200805-18
vendor-advisory
x_refsource_GENTOO
28754
third-party-advisory
x_refsource_SECUNIA
28758
third-party-advisory
x_refsource_SECUNIA
FEDORA-2008-1435
vendor-advisory
x_refsource_FEDORA
MDVSA-2008:048
vendor-advisory
x_refsource_MANDRIVA
28839
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now