Back to search
CVE-2009-2654
Published: Aug 3, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
ADV-2009-2142
vdb-entry
x_refsource_VUPEN
36141
third-party-advisory
x_refsource_SECUNIA
ADV-2009-2006
vdb-entry
x_refsource_VUPEN
20090727 Re: URL spoofing bug involving Firefox's error pages and document.write
mailing-list
x_refsource_BUGTRAQ
RHSA-2009:1430
vendor-advisory
x_refsource_REDHAT
http://blog.mozilla.com/security/2009/07/28/url-bar-spoofing-vulnerability/
x_refsource_CONFIRM
266148
vendor-advisory
x_refsource_SUNALERT
https://bugzilla.mozilla.org/show_bug.cgi?id=451898
x_refsource_CONFIRM
36001
third-party-advisory
x_refsource_SECUNIA
USN-811-1
vendor-advisory
x_refsource_UBUNTU
35803
vdb-entry
x_refsource_BID
36670
third-party-advisory
x_refsource_SECUNIA
36669
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:9686
vdb-entry
signature
x_refsource_OVAL
FEDORA-2009-8288
vendor-advisory
x_refsource_FEDORA
36126
third-party-advisory
x_refsource_SECUNIA
RHSA-2009:1432
vendor-advisory
x_refsource_REDHAT
http://www.mozilla.org/security/announce/2009/mfsa2009-44.html
x_refsource_CONFIRM
FEDORA-2009-8279
vendor-advisory
x_refsource_FEDORA
20090724 URL spoofing bug involving Firefox's error pages and document.write
mailing-list
x_refsource_BUGTRAQ
56717
vdb-entry
x_refsource_OSVDB
1022603
vdb-entry
x_refsource_SECTRACK
http://es.geocities.com/jplopezy/firefoxspoofing.html
x_refsource_MISC
DSA-1873
vendor-advisory
x_refsource_DEBIAN
RHSA-2009:1431
vendor-advisory
x_refsource_REDHAT
36435
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now