CVE-2009-2654 EXPLOIT
5.8
MEDIUM · CVSS 2.0 · EPSS 4.7% (pctl 92)
Patch early
A public exploit exists.
Description
Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.
Scoring
| CVSS | 5.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:P |
| EPSS | 4.75% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-08-03 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| mozilla | firefox |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mozilla Firefox 3.5.1 - Error Page Address Bar URI Spoofing | 2009-06-24 |
References
- http://blog.mozilla.com/security/2009/07/28/url-bar-spoofing-vulnerability/
- http://es.geocities.com/jplopezy/firefoxspoofing.html
- http://osvdb.org/56717
- http://secunia.com/advisories/36001
- http://secunia.com/advisories/36126
- http://secunia.com/advisories/36141
- http://secunia.com/advisories/36435
- http://secunia.com/advisories/36669
- http://secunia.com/advisories/36670
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-266148-1
- http://www.debian.org/security/2009/dsa-1873
- http://www.mozilla.org/security/announce/2009/mfsa2009-44.html
- http://www.redhat.com/support/errata/RHSA-2009-1430.html
- http://www.redhat.com/support/errata/RHSA-2009-1431.html
- http://www.redhat.com/support/errata/RHSA-2009-1432.html
- http://www.securityfocus.com/archive/1/505242/30/0/threaded
- http://www.securityfocus.com/archive/1/505265
- http://www.securityfocus.com/bid/35803
- http://www.securitytracker.com/id?1022603
- http://www.vupen.com/english/advisories/2009/2006
→ the Explorer · watch your stack · NVD