CVE-2009-0652

The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233.  NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 73.32%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
𝑥
≤ 3.0.6
mozillafirefox_esr
𝑥
≤ 3.0.6
mozillafirefox
1.0
mozillafirefox_esr
1.0
mozillafirefox
1.0.1
mozillafirefox_esr
1.0.1
mozillafirefox
1.0.2
mozillafirefox_esr
1.0.2
mozillafirefox
1.0.3
mozillafirefox_esr
1.0.3
mozillafirefox
1.0.4
mozillafirefox_esr
1.0.4
mozillafirefox
1.0.5
mozillafirefox_esr
1.0.5
mozillafirefox
1.0.6
mozillafirefox_esr
1.0.6
mozillafirefox
1.0.7
mozillafirefox_esr
1.0.7
mozillafirefox
1.0.8
mozillafirefox_esr
1.0.8
mozillafirefox
1.5
mozillafirefox_esr
1.5
mozillafirefox
1.5.0.1
mozillafirefox_esr
1.5.0.1
mozillafirefox
1.5.0.2
mozillafirefox_esr
1.5.0.2
mozillafirefox
1.5.0.3
mozillafirefox_esr
1.5.0.3
mozillafirefox
1.5.0.4
mozillafirefox_esr
1.5.0.4
mozillafirefox
1.5.0.5
mozillafirefox_esr
1.5.0.5
mozillafirefox
1.5.0.6
mozillafirefox_esr
1.5.0.6
mozillafirefox
1.5.0.7
mozillafirefox_esr
1.5.0.7
mozillafirefox
1.5.0.8
mozillafirefox_esr
1.5.0.8
mozillafirefox
1.5.0.9
mozillafirefox_esr
1.5.0.9
mozillafirefox
1.5.0.10
mozillafirefox_esr
1.5.0.10
mozillafirefox
1.5.0.11
mozillafirefox_esr
1.5.0.11
mozillafirefox
1.5.0.12
mozillafirefox_esr
1.5.0.12
mozillafirefox
2.0
mozillafirefox_esr
2.0
mozillafirefox
2.0.0.1
mozillafirefox_esr
2.0.0.1
mozillafirefox
2.0.0.2
mozillafirefox_esr
2.0.0.2
mozillafirefox
2.0.0.3
mozillafirefox_esr
2.0.0.3
mozillafirefox
2.0.0.4
mozillafirefox_esr
2.0.0.4
mozillafirefox
2.0.0.5
mozillafirefox_esr
2.0.0.5
mozillafirefox
2.0.0.6
mozillafirefox_esr
2.0.0.6
mozillafirefox
2.0.0.7
mozillafirefox_esr
2.0.0.7
mozillafirefox
2.0.0.8
mozillafirefox_esr
2.0.0.8
mozillafirefox
2.0.0.9
mozillafirefox_esr
2.0.0.9
mozillafirefox
2.0.0.10
mozillafirefox_esr
2.0.0.10
mozillafirefox
2.0.0.11
mozillafirefox_esr
2.0.0.11
mozillafirefox
2.0.0.12
mozillafirefox_esr
2.0.0.12
mozillafirefox
2.0.0.13
mozillafirefox_esr
2.0.0.13
mozillafirefox
2.0.0.14
mozillafirefox_esr
2.0.0.14
mozillafirefox
2.0.0.15
mozillafirefox_esr
2.0.0.15
mozillafirefox
2.0.0.16
mozillafirefox_esr
2.0.0.16
mozillafirefox
2.0.0.17
mozillafirefox_esr
2.0.0.17
mozillafirefox
2.0.0.18
mozillafirefox_esr
2.0.0.18
mozillafirefox
2.0.0.19
mozillafirefox_esr
2.0.0.19
mozillafirefox
2.0.0.20
mozillafirefox_esr
2.0.0.20
mozillafirefox
3.0
mozillafirefox_esr
3.0
mozillafirefox
3.0.1
mozillafirefox_esr
3.0.1
mozillafirefox
3.0.2
mozillafirefox_esr
3.0.2
mozillafirefox
3.0.3
mozillafirefox_esr
3.0.3
mozillafirefox
3.0.4
mozillafirefox_esr
3.0.4
mozillafirefox
3.0.5
mozillafirefox_esr
3.0.5
mozillaseamonkey
𝑥
≤ 1.1.14
mozillaseamonkey
1.0
mozillaseamonkey
1.0.1
mozillaseamonkey
1.0.2
mozillaseamonkey
1.0.3
mozillaseamonkey
1.0.5
mozillaseamonkey
1.0.6
mozillaseamonkey
1.0.7
mozillaseamonkey
1.0.8
mozillaseamonkey
1.0.9
mozillaseamonkey
1.1
mozillaseamonkey
1.1:alpha
mozillaseamonkey
1.1:beta
mozillaseamonkey
1.1.1
mozillaseamonkey
1.1.2
mozillaseamonkey
1.1.3
mozillaseamonkey
1.1.4
mozillaseamonkey
1.1.5
mozillaseamonkey
1.1.6
mozillaseamonkey
1.1.7
mozillaseamonkey
1.1.8
mozillaseamonkey
1.1.9
mozillaseamonkey
1.1.10
mozillaseamonkey
1.1.11
mozillaseamonkey
1.1.12
mozillaseamonkey
1.1.13
mozillathunderbird
𝑥
≤ 2.0.0.20
mozillathunderbird_esr
𝑥
≤ 2.0.0.20
mozillathunderbird
2.0.0.0
mozillathunderbird_esr
2.0.0.0
mozillathunderbird
2.0.0.4
mozillathunderbird_esr
2.0.0.4
mozillathunderbird
2.0.0.5
mozillathunderbird_esr
2.0.0.5
mozillathunderbird
2.0.0.6
mozillathunderbird_esr
2.0.0.6
mozillathunderbird
2.0.0.9
mozillathunderbird_esr
2.0.0.9
mozillathunderbird
2.0.0.12
mozillathunderbird_esr
2.0.0.12
mozillathunderbird
2.0.0.14
mozillathunderbird_esr
2.0.0.14
mozillathunderbird
2.0.0.16
mozillathunderbird_esr
2.0.0.16
mozillathunderbird
2.0.0.17
mozillathunderbird_esr
2.0.0.17
mozillathunderbird
2.0.0.18
mozillathunderbird_esr
2.0.0.18
mozillathunderbird
2.0.0.19
mozillathunderbird_esr
2.0.0.19
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
dapper
ignored
gutsy
ignored
hardy
ignored
intrepid
dne
jaunty
dne
karmic
dne
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected
iceape
dapper
dne
gutsy
ignored
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
seamonkey
dapper
dne
gutsy
dne
hardy
Fixed 1.1.17+nobinonly-0ubuntu0.8.04.1
released
intrepid
Fixed 1.1.17+nobinonly-0ubuntu0.8.10.1
released
jaunty
Fixed 1.1.17+nobinonly-0ubuntu0.9.04.1
released
karmic
Fixed 1.1.17+nobinonly-0ubuntu1
released
lucid
Fixed 1.1.17+nobinonly-0ubuntu1
released
maverick
Fixed 1.1.17+nobinonly-0ubuntu1
released
natty
Fixed 1.1.17+nobinonly-0ubuntu1
released
oneiric
Fixed 1.1.17+nobinonly-0ubuntu1
released
xulrunner
dapper
dne
gutsy
ignored
hardy
ignored
intrepid
ignored
jaunty
ignored
karmic
ignored
lucid
dne
maverick
dne
natty
dne
oneiric
dne
xulrunner-1.9
dapper
dne
gutsy
ignored
hardy
Fixed 1.9.0.9+nobinonly-0ubuntu0.8.04.1
released
intrepid
Fixed 1.9.0.9+nobinonly-0ubuntu0.8.10.1
released
jaunty
Fixed 1.9.0.9+nobinonly-0ubuntu0.9.04.1
released
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
xulrunner-1.9.1
dapper
dne
gutsy
dne
hardy
dne
intrepid
dne
jaunty
Fixed 1.9.1+nobinonly-0ubuntu0.9.04.1
released
karmic
Fixed 1.9.1~rc2+nobinonly-0ubuntu1
released
lucid
dne
maverick
dne
natty
dne
oneiric
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
MozillaFirefox
suse enterprise sap 12 SP5
68.1.0-109.92.1
fixed
suse enterprise server 12 SP5
68.1.0-109.92.1
fixed
MozillaFirefox-translations-common
suse enterprise sap 12 SP5
68.1.0-109.92.1
fixed
suse enterprise server 12 SP5
68.1.0-109.92.1
fixed
References