CVE-2009-5017

CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.15 % (52th)
0.15% Progress
Affected Products 1
Advisories 1

Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Related CVEs
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2010-11-12 22:00:01
(14 years ago)
Updated Date
2010-12-01 05:00:00
(13 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox Beta2 3.6 and prior versions cpe:2.3:a:mozilla:firefox::beta2 <= 3.6
  Mozilla Firefox 3.6 Beta1 cpe:2.3:a:mozilla:firefox:3.6:beta1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...