// For flags

CVE-2008-0591

Mozilla information disclosure flaw

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by using a timer to change the window focus, aka the "dialog refocus bug" or "ffclick2".

Mozilla Firefox versiones anteriores a 2.0.0.12 y Thunderbird versiones anteriores a 2.0.0.12, no administra apropiadamente un temporizador de retardo utilizado en los diálogos de confirmación, que podría permitir a atacantes remotos engañar a los usuarios para que confirmen una acción no segura, como la ejecución remota de archivos, mediante el uso de un temporizador para cambiar el enfoque de ventana, también conocido como el "dialog refocus bug" o "ffclick2".

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-02-05 CVE Reserved
  • 2008-02-08 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2024-09-27 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
References (63)
URL Tag Source
http://archives.neohapsis.com/archives/fulldisclosure/2007-06/0026.html Mailing List
http://browser.netscape.com/releasenotes X_refsource_confirm
http://secunia.com/advisories/29567 Third Party Advisory
http://secunia.com/advisories/30327 Third Party Advisory
http://secunia.com/advisories/30620 Third Party Advisory
http://securityreason.com/securityalert/2781 Third Party Advisory
http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html X_refsource_confirm
http://wiki.rpath.com/Advisories:rPSA-2008-0051 X_refsource_confirm
http://wiki.rpath.com/Advisories:rPSA-2008-0093 X_refsource_confirm
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093 X_refsource_confirm
http://www.mozilla.org/security/announce/2008/mfsa2008-08.html X_refsource_confirm
http://www.securityfocus.com/archive/1/470446/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/487826/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/488002/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/488971/100/0/threaded Mailing List
http://www.securityfocus.com/bid/24293 Vdb Entry
http://www.securityfocus.com/bid/27683 Vdb Entry
http://www.securitytracker.com/id?1019339 Vdb Entry
http://www.vupen.com/english/advisories/2008/0453/references Vdb Entry
http://www.vupen.com/english/advisories/2008/0454/references Vdb Entry
http://www.vupen.com/english/advisories/2008/0627/references Vdb Entry
http://www.vupen.com/english/advisories/2008/1793/references Vdb Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=376473 X_refsource_confirm
https://issues.rpath.com/browse/RPL-1995 X_refsource_confirm
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10900 Signature
URL Date SRC
http://lcamtuf.coredump.cx/ffclick2 2024-08-07
URL Date SRC
URL Date SRC
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00006.html 2018-10-15
http://secunia.com/advisories/28754 2018-10-15
http://secunia.com/advisories/28758 2018-10-15
http://secunia.com/advisories/28766 2018-10-15
http://secunia.com/advisories/28808 2018-10-15
http://secunia.com/advisories/28818 2018-10-15
http://secunia.com/advisories/28839 2018-10-15
http://secunia.com/advisories/28864 2018-10-15
http://secunia.com/advisories/28865 2018-10-15
http://secunia.com/advisories/28877 2018-10-15
http://secunia.com/advisories/28879 2018-10-15
http://secunia.com/advisories/28924 2018-10-15
http://secunia.com/advisories/28939 2018-10-15
http://secunia.com/advisories/28958 2018-10-15
http://secunia.com/advisories/29049 2018-10-15
http://secunia.com/advisories/29086 2018-10-15
http://secunia.com/advisories/29164 2018-10-15
http://secunia.com/advisories/29167 2018-10-15
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1 2018-10-15
http://www.debian.org/security/2008/dsa-1484 2018-10-15
http://www.debian.org/security/2008/dsa-1485 2018-10-15
http://www.debian.org/security/2008/dsa-1489 2018-10-15
http://www.debian.org/security/2008/dsa-1506 2018-10-15
http://www.gentoo.org/security/en/glsa/glsa-200805-18.xml 2018-10-15
http://www.mandriva.com/security/advisories?name=MDVSA-2008:048 2018-10-15
http://www.mandriva.com/security/advisories?name=MDVSA-2008:062 2018-10-15
http://www.redhat.com/support/errata/RHSA-2008-0103.html 2018-10-15
http://www.redhat.com/support/errata/RHSA-2008-0104.html 2018-10-15
http://www.redhat.com/support/errata/RHSA-2008-0105.html 2018-10-15
http://www.ubuntu.com/usn/usn-576-1 2018-10-15
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00274.html 2018-10-15
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00309.html 2018-10-15
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00381.html 2018-10-15
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00905.html 2018-10-15
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00946.html 2018-10-15
https://access.redhat.com/security/cve/CVE-2008-0591 2008-02-08
https://bugzilla.redhat.com/show_bug.cgi?id=431751 2008-02-08
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
<= 2.0.0.11
Search vendor "Mozilla" for product "Firefox" and version " <= 2.0.0.11"
-
Affected
Mozilla
Search vendor "Mozilla"
Thunderbird
Search vendor "Mozilla" for product "Thunderbird"
<= 2.0.0.11
Search vendor "Mozilla" for product "Thunderbird" and version " <= 2.0.0.11"
-
Affected