CVE-2008-5913

CVSS v2.0 4.9 (Medium)
49% Progress
EPSS 0.26 % (67th)
0.26% Progress
Affected Products 2
Advisories 9

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."

CVE Status
PUBLISHED
CNA
MITRE
Published Date
2009-01-20 16:30:00
(15 years ago)
Updated Date
2017-09-29 01:32:52
(7 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 3.5 cpe:2.3:a:mozilla:firefox:3.5
  Mozilla Firefox 3.5.1 cpe:2.3:a:mozilla:firefox:3.5.1
  Mozilla Firefox 3.5.2 cpe:2.3:a:mozilla:firefox:3.5.2
  Mozilla Firefox 3.5.3 cpe:2.3:a:mozilla:firefox:3.5.3
  Mozilla Firefox 3.5.4 cpe:2.3:a:mozilla:firefox:3.5.4
  Mozilla Firefox 3.5.5 cpe:2.3:a:mozilla:firefox:3.5.5
  Mozilla Firefox 3.5.6 cpe:2.3:a:mozilla:firefox:3.5.6
  Mozilla Firefox 3.5.7 cpe:2.3:a:mozilla:firefox:3.5.7
  Mozilla Firefox 3.5.8 cpe:2.3:a:mozilla:firefox:3.5.8
  Mozilla Firefox 3.5.9 cpe:2.3:a:mozilla:firefox:3.5.9

Configuration #2

    CPE23 From Up To
  Mozilla Firefox 3.6 cpe:2.3:a:mozilla:firefox:3.6
  Mozilla Firefox 3.6.2 cpe:2.3:a:mozilla:firefox:3.6.2
  Mozilla Firefox 3.6.3 cpe:2.3:a:mozilla:firefox:3.6.3
  Mozilla Firefox 3.6.4 cpe:2.3:a:mozilla:firefox:3.6.4

Configuration #3

    CPE23 From Up To
  Mozilla Seamonkey 2.0.4 and prior versions cpe:2.3:a:mozilla:seamonkey <= 2.0.4
  Mozilla Seamonkey 1.0 cpe:2.3:a:mozilla:seamonkey:1.0
  Mozilla Seamonkey 1.0 Alpha cpe:2.3:a:mozilla:seamonkey:1.0:alpha
  Mozilla Seamonkey 1.0 Beta cpe:2.3:a:mozilla:seamonkey:1.0:beta
  Mozilla Seamonkey 1.0.1 cpe:2.3:a:mozilla:seamonkey:1.0.1
  Mozilla Seamonkey 1.0.2 cpe:2.3:a:mozilla:seamonkey:1.0.2
  Mozilla Seamonkey 1.0.3 cpe:2.3:a:mozilla:seamonkey:1.0.3
  Mozilla Seamonkey 1.0.4 cpe:2.3:a:mozilla:seamonkey:1.0.4
  Mozilla Seamonkey 1.0.5 cpe:2.3:a:mozilla:seamonkey:1.0.5
  Mozilla Seamonkey 1.0.6 cpe:2.3:a:mozilla:seamonkey:1.0.6
  Mozilla Seamonkey 1.0.7 cpe:2.3:a:mozilla:seamonkey:1.0.7
  Mozilla Seamonkey 1.0.8 cpe:2.3:a:mozilla:seamonkey:1.0.8
  Mozilla Seamonkey 1.0.9 cpe:2.3:a:mozilla:seamonkey:1.0.9
  Mozilla Seamonkey 1.1 cpe:2.3:a:mozilla:seamonkey:1.1
  Mozilla Seamonkey 1.1 Alpha cpe:2.3:a:mozilla:seamonkey:1.1:alpha
  Mozilla Seamonkey 1.1 Beta cpe:2.3:a:mozilla:seamonkey:1.1:beta
  Mozilla Seamonkey 1.1.1 cpe:2.3:a:mozilla:seamonkey:1.1.1
  Mozilla Seamonkey 1.1.2 cpe:2.3:a:mozilla:seamonkey:1.1.2
  Mozilla Seamonkey 1.1.3 cpe:2.3:a:mozilla:seamonkey:1.1.3
  Mozilla Seamonkey 1.1.4 cpe:2.3:a:mozilla:seamonkey:1.1.4
  Mozilla Seamonkey 1.1.5 cpe:2.3:a:mozilla:seamonkey:1.1.5
  Mozilla Seamonkey 1.1.6 cpe:2.3:a:mozilla:seamonkey:1.1.6
  Mozilla Seamonkey 1.1.7 cpe:2.3:a:mozilla:seamonkey:1.1.7
  Mozilla Seamonkey 1.1.8 cpe:2.3:a:mozilla:seamonkey:1.1.8
  Mozilla Seamonkey 1.1.9 cpe:2.3:a:mozilla:seamonkey:1.1.9
  Mozilla Seamonkey 1.1.10 cpe:2.3:a:mozilla:seamonkey:1.1.10
  Mozilla Seamonkey 1.1.11 cpe:2.3:a:mozilla:seamonkey:1.1.11
  Mozilla Seamonkey 1.1.12 cpe:2.3:a:mozilla:seamonkey:1.1.12
  Mozilla Seamonkey 1.1.13 cpe:2.3:a:mozilla:seamonkey:1.1.13
  Mozilla Seamonkey 1.1.14 cpe:2.3:a:mozilla:seamonkey:1.1.14
  Mozilla Seamonkey 1.1.15 cpe:2.3:a:mozilla:seamonkey:1.1.15
  Mozilla Seamonkey 1.1.16 cpe:2.3:a:mozilla:seamonkey:1.1.16
  Mozilla Seamonkey 1.1.17 cpe:2.3:a:mozilla:seamonkey:1.1.17
  Mozilla Seamonkey 2.0 cpe:2.3:a:mozilla:seamonkey:2.0
  Mozilla Seamonkey 2.0 Alpha 1 cpe:2.3:a:mozilla:seamonkey:2.0:alpha_1
  Mozilla Seamonkey 2.0 Alpha 2 cpe:2.3:a:mozilla:seamonkey:2.0:alpha_2
  Mozilla Seamonkey 2.0 Alpha 3 cpe:2.3:a:mozilla:seamonkey:2.0:alpha_3
  Mozilla Seamonkey 2.0 Beta 1 cpe:2.3:a:mozilla:seamonkey:2.0:beta_1
  Mozilla Seamonkey 2.0 Beta 2 cpe:2.3:a:mozilla:seamonkey:2.0:beta_2
  Mozilla Seamonkey 2.0 Rc1 cpe:2.3:a:mozilla:seamonkey:2.0:rc1
  Mozilla Seamonkey 2.0 Rc2 cpe:2.3:a:mozilla:seamonkey:2.0:rc2
  Mozilla Seamonkey 2.0.1 cpe:2.3:a:mozilla:seamonkey:2.0.1
  Mozilla Seamonkey 2.0.2 cpe:2.3:a:mozilla:seamonkey:2.0.2
  Mozilla Seamonkey 2.0.3 cpe:2.3:a:mozilla:seamonkey:2.0.3
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...