The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random number generator that is seeded only once per document object, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack." NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-5913.
CVSS Details
- CVSS 3.1 Base Score: 5.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/seamonkey.Upgrade www-client/firefox.Upgrade www-client/icecat.Upgrade www-client/seamonkey-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade net-libs/xulrunner.Upgrade dev-libs/nss.Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox-bin.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/thunderbird. | Oct 30, 2017 | Sep 15, 2010 |
| Mfsa2010 33 | — | Upgrade to Mozilla Firefox version 3.6.9Upgrade to Mozilla Firefox version 3.5.12 | Jun 14, 2012 | Sep 15, 2010 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.0.5 | Feb 3, 2012 | Sep 15, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub