The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses the current time for seeding of a random number generator, which makes it easier for remote attackers to guess the seed value via a brute-force attack, a different vulnerability than CVE-2008-5913.
CVSS Details
- CVSS 3.1 Base Score: 4.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade net-libs/xulrunner-bin.Upgrade mail-client/thunderbird-bin.Upgrade www-client/seamonkey-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/thunderbird.Upgrade www-client/firefox.Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey.Upgrade mail-client/mozilla-thunderbird.Upgrade net-libs/xulrunner.Upgrade www-client/icecat.Upgrade dev-libs/nss.Upgrade www-client/firefox-bin. | Oct 30, 2017 | Sep 15, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub