[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-3987Date: (C)2009-12-17   (M)2024-03-27


The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.8
Exploit Score: 10.0
Impact Score: 6.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1023346
SECTRACK-1023347
BID-37349
BID-37360
SECUNIA-37699
SECUNIA-37785
ADV-2009-3547
firefox-geckoactivexobject-info-disclosure(54798)
http://www.mozilla.org/security/announce/2009/mfsa2009-71.html
https://bugzilla.mozilla.org/show_bug.cgi?id=503451
https://bugzilla.redhat.com/show_bug.cgi?id=546729
oval:org.mitre.oval:def:7958

CPE    136
cpe:/a:mozilla:firefox:1.5:beta2
cpe:/a:mozilla:firefox:3.5.5
cpe:/a:mozilla:firefox:1.5:beta1
cpe:/a:mozilla:firefox:3.5.3
...
CWE    1
CWE-200
OVAL    3
oval:org.secpod.oval:def:300695
oval:org.secpod.oval:def:300750
oval:org.mitre.oval:def:7958

© SecPod Technologies