CVE-2008-0591

EUVD-2008-0601
Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by using a timer to change the window focus, aka the "dialog refocus bug" or "ffclick2".
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
𝑥
≤ 2.0.0.11
mozillathunderbird
𝑥
≤ 2.0.0.11
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
114
101
114
101
114
101
114
101
114
101
100
110
iceape
100
110
100
110
100
110
105
103
100
110
100
110
icedove
100
110
100
110
100
110
100
110
100
110
100
110
iceweasel
100
110
100
110
100
110
100
110
100
110
100
110
mozilla-thunderbird
114
101
114
101
114
101
100
110
100
110
100
110
seamonkey
100
110
100
110
100
110
100
110
114
101
114
101
thunderbird
100
110
100
110
100
110
114
101
114
101
114
101
xulrunner
100
110
105
103
105
103
114
101
114
101
114
101
References