peter bassill · operator
$ cve CVE-2009-2654 JSON

CVE-2009-2654 EXPLOIT

5.8
MEDIUM · CVSS 2.0 · EPSS 4.7% (pctl 92)

Patch early

A public exploit exists.

Description

Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.

Scoring

CVSS5.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:P
EPSS4.75% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2009-08-03
Last modified2026-06-16

Affected (1)

VendorProduct
mozillafirefox

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD