[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-0358Date: (C)2009-02-04   (M)2023-12-22


Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim's browser, as demonstrated by reading the response page of an https POST request.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.3
Exploit Score: 6.5
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: ADJACENT_NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1021667
BID-33598
SECUNIA-33799
SECUNIA-33809
SECUNIA-33831
SECUNIA-33841
SECUNIA-33846
SECUNIA-33869
ADV-2009-0313
FEDORA-2009-1399
MDVSA-2009:044
RHSA-2009:0256
SUSE-SA:2009:009
USN-717-1
http://blogs.imeta.co.uk/JDeabill/archive/2008/07/14/303.aspx
http://support.avaya.com/elmodocs2/security/ASA-2009-040.htm
http://www.mozilla.org/security/announce/2009/mfsa2009-06.html
https://bugzilla.mozilla.org/show_bug.cgi?id=441751
oval:org.mitre.oval:def:10610

CPE    6
cpe:/a:mozilla:firefox:3.0.4
cpe:/a:mozilla:firefox:3.0.5
cpe:/a:mozilla:firefox:3.0.2
cpe:/a:mozilla:firefox:3.0.3
...
CWE    1
CWE-200
OVAL    50
oval:org.secpod.oval:def:700342
oval:org.secpod.oval:def:400063
oval:org.secpod.oval:def:101926
oval:org.secpod.oval:def:101935
...

© SecPod Technologies