CVE-2009-1834 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 3.2% (pctl 88)
Patch early
A public exploit exists.
Description
Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 allows remote attackers to spoof the location bar via an IDN with invalid Unicode characters that are displayed as whitespace, as demonstrated by the \u115A through \u115E characters.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 3.23% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-06-12 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | seamonkey |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mozilla Firefox 3.0.10 / SeaMonkey 1.1.16 - Address Bar URI Spoofing | 2009-05-11 |
References
- http://osvdb.org/55162
- http://secunia.com/advisories/35331
- http://secunia.com/advisories/35415
- http://secunia.com/advisories/35431
- http://secunia.com/advisories/35439
- http://secunia.com/advisories/35468
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1
- http://www.debian.org/security/2009/dsa-1820
- http://www.mozilla.org/security/announce/2009/mfsa2009-25.html
- http://www.securityfocus.com/bid/35326
- http://www.securityfocus.com/bid/35388
- http://www.vupen.com/english/advisories/2009/1572
- https://bugzilla.mozilla.org/show_bug.cgi?id=479413
- https://bugzilla.redhat.com/show_bug.cgi?id=503573
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10436
- https://rhn.redhat.com/errata/RHSA-2009-1095.html
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.html
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.html
- http://osvdb.org/55162
→ the Explorer · watch your stack · NVD