The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade firefoxUpgrade xulrunnerUpgrade xulrunner-devel-unstableUpgrade xulrunner-devel | Dec 1, 2016 | Feb 20, 2009 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade dev-libs/nss.Upgrade net-libs/xulrunner.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/seamonkey-bin.Upgrade www-client/icecat.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/thunderbird.Upgrade www-client/firefox-bin. | Oct 30, 2017 | Feb 20, 2009 |
| Mfsa2009 15 | — | Upgrade to Mozilla Firefox version 3.0.9 | Jun 14, 2012 | Feb 20, 2009 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.15 | Feb 3, 2012 | Feb 20, 2009 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.21 | Feb 22, 2012 | Feb 20, 2009 |
| Oracle_linux | — | Upgrade xulrunner-devel-unstableUpgrade firefoxUpgrade xulrunnerUpgrade xulrunner-devel | Oct 16, 2024 | Feb 20, 2009 |
| Suse | — | Upgrade libfreebl3-32bitUpgrade libidl-32bitUpgrade mozilla-xulrunner190Upgrade mozilla-xulrunner192-32bitUpgrade mozilla-xulrunner192-translationsUpgrade mozilla-xulrunner192Upgrade mozilla-nss-x86Upgrade libidlUpgrade mozilla-nspr-32bitUpgrade mozilla-nsprUpgrade orbit2Upgrade MozillaFirefox-translations-commonUpgrade mozilla-xulrunner190-translationsUpgrade mozilla-xulrunner191-x86Upgrade MozillaFirefox-translationsUpgrade mozilla-xulrunner191-32bitUpgrade mozilla-xulrunner192-gnomeUpgrade mozilla-nspr-x86Upgrade mozilla-xulrunner190-32bitUpgrade MozillaFirefoxUpgrade orbit2-32bitUpgrade mozilla-xulrunner190-x86Upgrade orbit2-x86Upgrade gconf2-x86Upgrade libidl-x86Upgrade mozilla-xulrunner191Upgrade MozillaFirefox-translations-otherUpgrade gconf2Upgrade libfreebl3Upgrade mozilla-nssUpgrade mozilla-xulrunner191-gnomevfsUpgrade libfreebl3-x86Upgrade mozilla-xulrunner191-translationsUpgrade MozillaFirefox-branding-SLEDUpgrade mozilla-xulrunner190-gnomevfsUpgrade mozilla-nss-toolsUpgrade mozilla-xulrunner192-x86Upgrade mozilla-nss-32bitUpgrade gconf2-32bitUpgrade MozillaFirefox-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade xulrunner-1.9Upgrade firefox-3.0Upgrade abrowser | Nov 8, 2024 | Feb 20, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub