CVE-2008-5913

Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 20 Jan 2009, 16:00
Last modified:07 Aug 2024, 11:13

Vulnerability Summary

Overall Risk (default)
low
20/100
CVSS Score
4.9 MEDIUM
v2.0 (nvd)
EPSS Score
0.43% LOW
0% probability -0.03%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

20 Jan 2009, 16:00
Published
Vulnerability first disclosed
07 Aug 2024, 11:13
Last Modified
Vulnerability information updated

Description

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."

CVSS Metrics

  • v2.0MEDIUMScore: 4.9AV:N/AC:M/Au:S/C:P/I:P/A:N

EPSS Trends

Current EPSS score: 0.43% Percentile: 63%

Affected Systems

  • mozillafirefox

    3.5 | 3.5.1 | 3.5.2 | 3.5.3 | 3.5.4 | 3.5.5 | 3.5.6 | 3.5.7 | 3.5.8 | 3.5.9 | 3.6 | 3.6.2 | 3.6.3 | 3.6.4

  • mozillaseamonkey

    ≤ 2.0.4 | 1.0 | 1.0:alpha | 1.0:beta | 1.0.1 | 1.0.2 | 1.0.3 | 1.0.4 | 1.0.5 | 1.0.6 | 1.0.7 | 1.0.8 | 1.0.9 | 1.1 | 1.1:alpha | 1.1:beta | 1.1.1 | 1.1.2 | 1.1.3 | 1.1.4 | 1.1.5 | 1.1.6 | 1.1.7 | 1.1.8 | 1.1.9 | 1.1.10 | 1.1.11 | 1.1.12 | 1.1.13 | 1.1.14 | 1.1.15 | 1.1.16 | 1.1.17 | 2.0 | 2.0:alpha_1 | 2.0:alpha_2 | 2.0:alpha_3 | 2.0:beta_1 | 2.0:beta_2 | 2.0:rc1 | 2.0:rc2 | 2.0.1 | 2.0.2 | 2.0.3

References (25)