The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade xulrunner-devel-unstableUpgrade xulrunnerUpgrade xulrunner-develUpgrade firefox | Dec 1, 2016 | Feb 20, 2009 |
| Gentoo Linux | — | Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/mozilla-firefox.Upgrade net-libs/xulrunner.Upgrade www-client/firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade dev-libs/nss.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/icecat.Upgrade mail-client/thunderbird-bin.Upgrade www-client/seamonkey-bin.Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey.Upgrade www-client/firefox-bin.Upgrade net-libs/xulrunner-bin. | Oct 30, 2017 | Feb 20, 2009 |
| Mfsa2009 15 | — | Upgrade to Mozilla Firefox version 3.0.9 | Jun 14, 2012 | Feb 20, 2009 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.15 | Feb 3, 2012 | Feb 20, 2009 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.21 | Feb 22, 2012 | Feb 20, 2009 |
| Oracle_linux | — | Upgrade firefoxUpgrade xulrunner-develUpgrade xulrunnerUpgrade xulrunner-devel-unstable | Oct 16, 2024 | Feb 20, 2009 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade mozilla-nss-32bitUpgrade mozilla-xulrunner190-gnomevfsUpgrade gconf2Upgrade orbit2-32bitUpgrade mozilla-xulrunner191-translationsUpgrade mozilla-nssUpgrade orbit2-x86Upgrade libidl-x86Upgrade MozillaFirefox-develUpgrade libfreebl3-x86Upgrade gconf2-32bitUpgrade libfreebl3Upgrade mozilla-nss-toolsUpgrade mozilla-xulrunner191-gnomevfsUpgrade gconf2-x86Upgrade mozilla-xulrunner191Upgrade mozilla-xulrunner190-x86Upgrade mozilla-xulrunner192-x86Upgrade MozillaFirefox-branding-SLEDUpgrade MozillaFirefox-translations-commonUpgrade orbit2Upgrade mozilla-xulrunner190Upgrade mozilla-nspr-32bitUpgrade mozilla-xulrunner192-gnomeUpgrade mozilla-xulrunner190-32bitUpgrade libidlUpgrade mozilla-nsprUpgrade mozilla-xulrunner192-32bitUpgrade libfreebl3-32bitUpgrade MozillaFirefox-translationsUpgrade MozillaFirefoxUpgrade mozilla-xulrunner190-translationsUpgrade mozilla-nspr-x86Upgrade mozilla-nss-x86Upgrade mozilla-xulrunner192-translationsUpgrade mozilla-xulrunner191-32bitUpgrade libidl-32bitUpgrade mozilla-xulrunner191-x86Upgrade mozilla-xulrunner192 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade firefox-3.0Upgrade xulrunner-1.9Upgrade abrowser | Nov 8, 2024 | Feb 20, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub